Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

vulnerable item exclusion rule did not close some existing vulnerable items

RavishShett
Tera Contributor

Hi all,

 

We created some vulnerable item exclusion rules, and it closed some and did not close others.  the condition was simple. it was looking for some VITs where the vulnerability is XYZ. what could be the reason for some VITs not getting closed? these VITs are in open state.

 

Thanks,

Ravish

2 REPLIES 2

RavishShett
Tera Contributor

bump

andy_ojha
ServiceNow Employee

Hey there,


It's tough to say what is happening with limited info here.

The primary goal of Exclusion Rules is actually not to Close VITs, rather it is to control what Detections lead to the creation of VITs (i.e. it can be used to prevent VITs from being created).

In certain circumstances, if you have already imported data and created VITs -> and then created Exclusion Rules after that -> Exclusion Rules do not automatically go back and retrofit VITs to close them out.

In this situation, you have to leverage a combo of

A) Auto-Close Rules (to handle existing VITs we already created, and are no longer being imported on future integration imports, after creating the Exclusion Rule)
B) Exclusion Rules -> from the point when the rules were created, to prevent future VITs from being created (it does not automatically go search for VITs that meet that criteria and close them out)

 

There was a similar post here, and these details should help (the sys_property called, "sn_vul.close_vit_with_excluded_detections" and the video from John Gibbons) from the post below:

https://www.servicenow.com/community/secops-forum/cannot-apply-exclusion-rules/m-p/3500601