Delete all your vulnerable item records and related data in Vulnerability Response

  • Release version: Xanadu
  • Updated August 1, 2024
  • 3 minutes to read
  • Permanently remove all Vulnerability Response data (vulnerable items or vulnerable item detections) and related data and records from the from the Vulnerability Response application in your ServiceNow AI Platform® instance.

    Before you begin

    Delete vulnerable item detection records, vulnerable items, vulnerability groups, and any related records in the Vulnerability Response application from your instance. Use this process to clean out your instance to import data with a fresh start from your third-party integrations, or, as a prerequisite to returning the vulnerable item (VI) key configuration to its default setting. For more information on configuring the VI key, see Configure the vulnerable item key.

    Note:
    This action deletes all the vulnerable item records and any related data from your instance. This data once deleted cannot be retrieved. It also requires you to suspend data import and disable your active third-party integrations with Vulnerability Response.

    Deleting your vulnerable item data with this process prior to changing the VI key configuration is required. Removing all data ensures that all your vulnerable items and vulnerable item detections are mapped and updated with the most current data starting with the next Import.

    Verify the following conditions apply prior to deleting your data:
    • You have v10.0 or later of Vulnerability Response installed. For more information, see Vulnerability Response vulnerable item detections from third-party integrations.
    • You want to disable Include port and return the VI key configuration to its default setting.
    • You have existing vulnerable items and vulnerable item detections but do not want, or need to update and keep them.
    • You have determined you want to remove all existing Vulnerability Response data and related records to clean up your instance.
    Role required: sn_vul.vulnerability_admin

    Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.

    Procedure

    1. Navigate to All > Vulnerability Response > Vulnerability Integrations.
    2. Record all of the active integrations that are displayed.

      All of the active integrations listed with scheduled jobs are disabled prior to deleting all of your vulnerable items and related data so that no new data is imported during the data removal. Recording this list helps you activate your integrations after the delete is completed.

    3. Review the How to delete Existing Vulnerability Response Data for Reimport article in the HI Knowledge Base.
    4. If a warning message is displayed that prevents you from writing to the Active column, to disable active integrations, follow these steps.
      1. In the Name column click an item to open the record.
      2. If you cannot edit the Active check box, click the here link to edit the record.
      3. Click the Active check box to disable the integration and the cancel the next scheduled job.
      4. Click Update to save your changes and return to the list.
      5. Verify you have disabled any active integrations from the Integrations list.
        After you disable an integration, it is no longer displayed on the active integrations list. To view a list inactive integrations, and locate all the integrations you disabled after you delete all your vulnerability data, in the Active column at the top, enter =false.
    5. Continue with the steps in the KB article for deleting your existing vulnerability data.
    6. After you have confirmed that all data is successfully deleted, navigate to Vulnerability Response > Administration > Configure VI granularity.
    7. On the form:
      • If you deleted data because you prefer to build your vulnerability data to include port from a fresh import, enable Include port and click Save.
      • If you deleted data because you want to return the VI key to its default setting, disable Include port and click Save.
      For more information, see Configure the vulnerable item key.