Working with unmatched CIs
As a Vulnerability Manager and Analyst, you can view and reclassify unmatched Configuration Items (CIs), reconcile unmatched discovered items, reapply CI lookup rules on the selected discovered items, and de-duplicate existing CIs.
See the CI matching in Vulnerability Response knowledge base article [KB0998706] for more information about CI matching rule concepts and how CI matching works.
- View and reclassify unmatched configuration items
Configuration items (CIs) that are not found in the Configuration Management Database (CMDB) are placed in a viewable list of discovered items. This list offers a convenient way to reclassify unmatched CIs. - Reconcile unmatched discovered items
Create a scheduled job to reconcile unmatched discovered items. - Steps to help prevent duplicate or orphaned records after running Vulnerability Response CI lookup rules
Take steps to help prevent duplicate or orphan records resulting from matching (configuration items (CIs) within the CMDB. - De-duplicating existing configuration items
Whenever configuration items (CIs) are updated through a deduplication task, the discovered items (DIs) that are related to those CIs are also updated. The vulnerable items (VIs) and detections are also updated with the CI. - Resolve remediation tasks
The flexibility inherent in Vulnerability Response allows you to remediate vulnerabilities in whatever way suits your security organization.
Parent Topic:Vulnerability Response remediation overview