Vulnerability Response Unclassed Hardware Records

Steve Ross1
Tera Contributor

Our Tenable integration is creating Unclassed Hardware records in the CMDB, currently the name is being populated with the NetBIOS information and we would prefer to have the DNS name instead.

I am looking for some guidance on two things:
1. Is there a way for us to control how the Unclassed Hardware record fields are being populated. Can we use the DNS name instead of the NetBIOS name for the name field?

2. Is there any guidance on how to run discovery on the Unclassed Hardware records so we can make sure they are added to the CMDB?

2 REPLIES 2

Wojciech Werysz
Kilo Guru

 

Hi, did you try to check:

 

sn_sec_cmn_src_cmdb_map.list - list of lookup rules configured in Host Import Map

 

[…] New functionality has been provided to extract the Host Names from FQDN/NETBIOS so that the CI lookup/new CI creation can be done on name attribute with just the hostname of the asset. This can be configured in Host Import Map (sn_sec_cmn_src_cmdb_map) for each scanner integration.ChangedYou might find improved performance on watch topic pages.

 

From <https://docs.servicenow.com/en-US/bundle/store-release-notes/page/release-notes/store/security-opera...>  […]

Ravali
Tera Contributor

Had a similar question on how to control the creation of unclassed hardware CI with name and how  to make the discovery or indentification rules pick up the unclassed CI which VR created and reclassify?