Regarding the CI placeholder record created during vulnerability data ingestion.
After capturing vulnerability data, if the CI look up does not match the CI, a placeholder record is recognized to be created in cmdb_ci_unclassed_hardware. Reference: https://www.servicenow.com/docs/bundle/xanadu-security-management/page/product/vul...
