Global Excludes List allows administrators to define global IP exclusions lists that
work across Discovery schedules that discover configuration items, IP
addresses, or networks. The list helps to prevent access to sensitive IPs as it blocks
discovery when the IP is on the exclusion list. This feature is only applicable for Horizontal
Discovery starting in the Rome release.
Before you begin
Global IP exclude ranges are active by default. To deactivate, uncheck the Active check box. This makes the records inactive and the entries aren't excluded from Discovery. You can add a single IP or an IP range to the Global Excludes list. The IP exclusion list [ip_exclusion] table references existing IP collection tables and supports three types of collections: IP
address list, IP address subnet, and IP address range.
Note: Use of Global Excludes List for IP addresses and ranges is not supported for IPv6 addresses. While the UI still allows users to add IPv6 addresses to the list, these addresses get ignored and are skipped from the exclusion
process during Discovery.
Role required: discovery_admin or agent_admin role
Procedure
-
Navigate to .
-
Click New to create a new IP exclusion record.
-
In the IP Excluded box, click the search icon to bring up the IP collections
window.
-
Select one of the IP collections listed or click New to
bring up the IP Collections wizard.
-
From the IP Collections wizard, select one of the three types of collections you want to create and fill in the necessary details.
For each type, you can add a description on why you want to exclude particular IPs or which IPs are excluded.
- IP Address List
Enter the name and then Save. The related list then shows at the bottom of the page. From the collections list, pick an existing item or click New to
create a new list. Click Update. Remember the name you created. This new name is added to the collection list. Select this name from the list and click Submit again. This
address list is added to the IP Exclusion list.
-
Navigate to and select a schedule.
-
If the schedule is for discovering configuration items, IP addresses, or
networks, you can view the Global IP Exclusion tab at the bottom of the
page.
Result
When the scheduled
Discovery runs, it skips the discovery of all IPs that are part of the active Global IP Exclusion record. All the rest of the IPs should be discovered.
Note: Overriding behavior is not applicable when the Discovery schedule has active Global IP exclusions.
If you try to run a Quick Discovery that includes an excluded IP, you
will see an error message and Discovery will not be triggered.