---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Manual ingestion of vulnerabilities

# Manual ingestion of vulnerabilities {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Manually ingest vulnerabilities into the Vulnerability Response application so that
you can remediate them quickly without having to wait for scanner results.

Third-party scanners such as Rapid7 help import vulnerability data into Vulnerability Response and process the data to report the findings. With Manual Ingestion
integration, you can proactively ingest the vulnerabilities and remediate them instead of waiting
for scanners to report the assets that are at risk. Manual ingestion of vulnerabilities
effectively protects the assets against unknown threats such as zero-day exploits.

## Manual ingestion of vulnerabilities {#manually-ingest-vulnerabilities__section_ccb_x1s_v5b}

You can import the vulnerability data by uploading a template in the following file formats:

* Excel
* Comma-separated value (CSV)
{#manually-ingest-vulnerabilities__ul_rgk_gx1_25b}

To access and download the template, navigate to AllVulnerability ResponseManual Vulnerability Item IngestionUpload File UI.  
Ensure that you follow these key points while populating the records in the template:

* Do not make any typing errors in the Severity/ State column records. If there is a typing error, the record is skipped.
* Do not change the column names.
* Do not put column names in any row except the first row.
* Do not change the order of the sheets in the Microsoft Excel template. The vulnerabilities data must always be present in the second sheet.
* Do not put vulnerabilities details in any sheet except the Input Manual Detections sheet.
* Do not use any character except alphanumeric and special characters such as dash (-), period (.), plus (+), underscore ( _ ), space, brackets '(' ')', and at symbol (@) for the filename.
{#manually-ingest-vulnerabilities__ul_qch_qnr_v5b}

For instructions on how to populate the data in the template, see [Template for manual ingestion of vulnerabilities](https://www.servicenow.com/docs/K9HcgYHE9yx5ilGGUMKbwQ "The template provides columns that must be filled with vulnerability and configuration item (CI) data. After the template is populated and uploaded, the data is processed.").

Starting with v24.0.6 of Vulnerability Response, you can also create additional columns in the Microsoft Excel template. For more information, see [KB1646630](https://support.servicenow.com/nav_to.do?uri=/kb?id=kb_article_view&sys_kb_id=7fb3462b9348d2d4d744b94c5cba1001).

## Manual Ingestion integrations {#manually-ingest-vulnerabilities__section_ift_yxh_x1b}

The integration is triggered when a file is uploaded. Based on the type of file uploaded, the
related integration is triggered.

To view the integrations, navigate to AllVulnerability ResponseManual Vulnerability Item IngestionIntegrations.

The following base system Manual Ingestion integrations are available by default.  
{#manually-ingest-vulnerabilities__table_sbn_qlp_dt__entry__2}

| Integration type | Description |
|-|-|
| Manual Ingestion Excel Integration | Retrieves data by fetching the latest Microsoft Excel file uploaded from the Vulnerability Ingestion Push Queue table and copies the attachment to the respective Integration run. |
| Manual Ingestion CSV Integration | Retrieves data by fetching the latest CSV file uploaded from the Vulnerability Ingestion Push Queue table and copies the attachment to the respective Integration run. |
[Table 1. Integrations]

{#manually-ingest-vulnerabilities__table_sbn_qlp_dt}  
The Manual Ingestion third-party integration creates an integration instance, by default, with the following two integration instance parameters:

* max_input_records: Defines the number of records that can be created in the template. If you add more records than what is specified in this parameter, the additional records are skipped. The number of records can be updated in the Value column. The recommended number of record creations in the template is 1000. Anything above this value can pose performance challenges.
* insert_fixed: Imports fixed vulnerability detections.
{#manually-ingest-vulnerabilities__ul_al1_p2h_g5b}

To view the integration instance parameters, navigate to AllVulnerability ResponseManual Vulnerability Item IngestionIntegrations and click the source instance of any integration. Alternatively, you can navigate
to AllVulnerability ResponseIntegration Instances and click Manual Ingestion.

*[\>]: and then


