Configuring auto-close rules
By configuring auto-close rules, you can automate the process of closing stale detections and findings associated with retired configuration items (CIs).
- Assets last scanned: Detections associated with assets that haven’t been scanned within the last 90 days are transitioned to Stale state.
- Detections last found: Detections that haven’t been found within the last 90 days. If you activate Detections last found record, then this feature requires a successful integration run of Rapid7 Comprehensive Vulnerable Item Integrations and Microsoft TVM Machine Vulnerabilities Integration (Full import) within the last seven days.
Starting with v30.3.3 of USEM parallel processing for auto close rules is supported. Previously, auto close rules ran as a single sequential job. With parallel processing, the system automatically creates multiple concurrent jobs based on data volume, significantly reducing execution time for large datasets. When you enable an auto close rule, the system evaluates the number of applicable items and determines the number of parallel jobs to create automatically. Parallelism is configured in code and requires no manual setup.
Configuration of auto-delete rules includes the following steps.
Create or edit auto-close rules
Create rules to close stale detections and findings associated with retired configuration items (CIs) automatically.
Before you begin
Role required: See Access control lists (ACLs) for administration rules