Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

SecOps Vulnerability Response Health dashboard

The Vulnerability Response Health dashboard is a tool designed to empower organizations with comprehensive insights into the implementation and usage of their Vulnerability Response applications.

The overall health assessment is determined by aggregating various critical factors across configuration, implementation, integration, performance, data, and process. View the aggregate dashboard for each category for the following applications:

  • Vulnerability Response
  • Application Vulnerability Response
  • Container Vulnerability Response
  • ​Configuration Compliance​

Installing the SecOps Vulnerability Response Health Dashboard

To install and configure the SecOps Vulnerability Response Health Dashboard for Vulnerability Response applications in your ServiceNow AI Platform instance, navigate to the ServiceNow® Store and activate the SecOps Health Analytics (sn_sec_analytics) plugin.

Required ServiceNow AI Platform roles

Roles required: sn_sec_analytics.admin, sn_sec_analytics.read

Scheduled job

To view the scheduled job, navigate to All > System Scheduler > Scheduled Jobs > Collect health dashboard metrics. The 'Collect health dashboard metrics' scheduled job is run daily at 00:00 hours. It generates the data for the SecOps Vulnerability Response Health dashboard. You can choose to run the scheduled job manually as well.

Use cases

For examples of how people in your organization would use this dashboard, see these use cases.

UserDashboard use
Vulnerability adminHelps you gain an understanding of the health score of the Vulnerability Response applications. It’s also helpful to highlight the areas that need improvement. The Vulnerability Response Health Dashboard deals with the implementation and usage health only. It doesn’t assist with management of vulnerabilities or assets.
Support adminHelps you to identify the performance, customization, and configuration issues using KPIs. Based on the application health, you can perform an extra analysis or provide a recommendation to the users.
Implementation partnerHelps you to evaluate the Vulnerability Response implementation health for configurations, add-ons, customizations, and integrations, and provide improvement recommendations for the users.

The SecOps Vulnerability Response Health Dashboard tabs

To view the SecOps Vulnerability Response Health dashboard, navigate to Security Operation Health > Vulnerability Response Health. Each color in the dashboard represents the following:

  • Green: Safe
  • Yellow: Warning
  • Red: Critical

This dashboard communicates the overall health score for the configuration and remediation health of the VR applications.

Image omitted: secops-vr-health-dashboard-summary.png
SecOps - VR Health dashboard - Summary tab

This dashboard displays the configuration and integration health of your implementation. It provides a holistic overview of the implementation performance.

Image omitted: secops-vr-health-dashboard-system-health.png
SecOps - VR Health dashboard - System Health tab

This dashboard displays the data health of the VR applications.

Image omitted: secops-vr-health-dashboard-rem-health-tab.png
SecOps - VR Health dashboard - Remediation Health tab

This dashboard displays the trends for the vulnerable item ingestion performance metrics for the past 30 days for the VR applications.

Image omitted: secops-vr-health-dashboard-trends.png
SecOps - VR Health dashboard - Trends tab

Reports

Note: The threshold values are a part of the base system. You can configure the values based on your requirements.

TitleDescription
Overall healthOverall health score for the VR applications. For more information, see the reports for the metrics.
ConfigurationOverall configuration health of the VR applications.
Implementation healthOverall implementation health of the VR applications.
Integration healthOverall integration health of the VR applications.
PerformanceOverall performance health score of the VR applications.
Data healthOverall data health of the VR applications.
Process healthOverall process health score of the VR applications.
TitleDescriptionConsiderations for improving performanceThreshold warningThreshold critical
Configuration
Auto-delete rulesDisplays the number of enabled auto-delete rules.Review and resolve the inactive auto-delete rules.31
Auto-close stale recordsCloses stale detections automatically. For more information, see the 'Automatically close stale detections in Vulnerability Response' topic in servicenow.com/docs.Reduce the volume of stale detections. Enable this option to close the stale detections that aren’t closed by the scanners.31
Implementation health
Customized script includesNumber of 'script includes' customized.Minimize customized 'script includes' for easier upgrades.1012
Business rules on the detections tableNumber of customized business rules in the detection table.Minimize business rules for easier upgrades.48
Customized business rulesNumber of customized business rules before creation of records in the CMDB.Use the default business rules on records.58
Upgrade conflictsConflicts such as business rules and scripts identified on an upgrade.Review and resolve the upgrade conflicts.1015
PA installed but not activatedIndicates if the Performance Analytics dashboard is not enabled.Activate the PA dashboard.1015
Integration health
Disabled integrationsNumber of integrations that have been disabled.Review and enable the required integrations.69
Failed integration runs in the past weekNumber of integration runs that weren’t successful in the past week.Review and resolve the cause of the failed integration runs.912
Performance
Slow business rules and scriptsBusiness rules and scripts whose average execution time greater than 10 ms and execution count greater than 10,000.Review and resolve the slow-running business rules.1015
Stalled integrationsNumber of integrations that were timed-out before completion.Review and resolve the cause of the stalled integrations.1015
Failed or stalled background jobsFailed or timed-out background jobs in the past week.Review and resolve the cause of the failed jobs.510
Slow queriesQueries whose average execution time is greater than 10 ms and execution count is greater than 10,000.Review and resolve the slow-running business rules.1015
TitleDescriptionConsiderations for improving performanceThreshold warningThreshold critical
Data Health
Discovered item matching rateNumber of discovered items matched to existing CIs.Review the health of your CMDB and the CI lookup rules logic.5020
Unmatched CIs in discovered itemsDiscovered items in unmatched state.Review the health of your CMDB and the CI lookup rules logic.912
Unused CI lookup rulesCI lookup rules that aren’t associated with any discovered item.Change the status of the unused CI lookup rules to inactive.46
Discovered item with no CIDiscovered item with no configuration item.Review and reapply CI lookup rules.912
Defective active recordsRecords without a configuration item or vulnerability.Retire the CIs using the CMDB CI Lifecycle Management option.Note: Deleting CIs directly can result in orphan VITs.4060
Remediation tasks without assignment groupActive remediation tasks whose assignment group is yet to be assigned.Assign remediation tasks to an assignment group and review the existing assignment rules.4060
Closed records without substateRecords that are closed without a substate.Provide information in the Reason field while closing the records.4050
Process Health
Active records without risk scoreActive records with a risk score of 0 or with no risk score assigned.Review and resolve the risk rules.4060
Unassigned active recordsRecords without an assignment group.Assign a group to the records and review the existing assignment rules.3050
Items without Remediation TargetItems without a remediation target date.Review and resolve the remediation target rules. These rules must include all the records.3050
Ungrouped active recordsRecords that aren’t included in a remediation task rule.Review the remediation task rules.4060
TitleDescription
Last 30 days vulnerable item ingestion performance metricsAverage time taken to ingest vulnerable items and process multiple rules in the past 30 days.