Bulk edit for false positive in the Vulnerability Manager Workspace
Mark one or more records (VITs, AVITs, CVITs, or TRs) as false positive concurrently using the bulk edit feature from the Vulnerability Manager Workspace instead of manually selecting each item.
Before you begin
Role required:
- sn_vul.vulnerability_analyst, or sn_vul.vulnerability_admin for host vulnerable items (VITs)
- sn_vul.app_sec_manager for application vulnerable items (AVITs)
- sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin for container vulnerable items (CVITs)
- sn_vulc.admin for configuration test results (TRs)
About this task
When you raise a false positive request for one or more records from the Bulk edit modal, a remediation task is created with the selected records.
Note:
When you raise a false positive request for the Application Vulnerable
Items (AVITs) using the bulk edit feature, the AVITs from the scanners with the Manage False positive with Servicenow parameter set to false are not updated.
- If you select AVITs from various scanners, some with the Manage False positive with Servicenow parameter set to true and other set to false, the AVITs linked to the scanners with the Manage False positive with Servicenow parameter set to false are not updated.
- If you select AVITs from only the scanners with the Manage False positive with Servicenow parameter set to false, the False positive option does not appear in the Reason field in the Bulk Edit modal.
Procedure
Result
In the Vulnerability Manager Workspace, on the List page, navigate to , open the corresponding state change approval record (VCA#) and check the status of your request in the Approval state column:
| Approval state | Result |
|---|---|
| Approved | The state of the Remediation Task transitions to Closed with the Reason as False positive. The state and reason are rolled down to the records. |
| Rejected | The state of the Remediation Task and its records doesn’t change. |
In the Activity stream of a record or remediation task, you can view the entire workflow of your request.