The Zurich release has arrived! Interested in new features and functionalities? Click here for more

Regarding SecOps-VR's Reconcile unmatched discovered items.

Ohki_Yamamoto
Tera Guru

In the following Docs' Reconcile unmatched discovered items, we understand that there is a function to re-execute CI LOOK UP for discovered items in the Unmatched state.

 

https://www.servicenow.com/docs/bundle/xanadu-security-management/page/product/vulnerability-respons...

 

For example, suppose that a placeholder record with the host name XXXX has been created as an unmatched CI.

Then, through Discovery, a new CI with the host name: XXXX is created.

 

In this case, the CI with the host name: XXXX is in a duplicate state.

 

If you run the Reconcile Unmatched Discovered Items job in this state, does the vulnerability match item originally linked to the placeholder record get relinked to the CI created through Discovery when CI LOOK UP is re-executed?

 

I would like to confirm whether the vulnerability match items are always re-linked to the CI created by Discovery rather than the placeholder record.

 

1 REPLY 1

Ohki_Yamamoto
Tera Guru

Also, can Reconcile unmatched discovered items be used for app vulnerabilities and container vulnerabilities?