Customize Scan Engine definitions
You can modify an existing definition to further customize and refine its scanning criteria.
Before you begin
Role required: Scan Engine admin (sn_se.scan_engine_admin) .
While only Scan Engine admins can modify definitions, any user with the Scan Engine user role can view them.
Procedure
Navigate to ALL > Impact > Platform Health > Definitions.
Select a definition number to open its details.
To modify a base system definition’s properties, select Override Definition.
When a definition is overridden, the base system definition will no longer be used in any scan (real-time, scheduled, update set, application, or on demand). All fields in the overridden definition become editable.
Modify the required and optional fields.
- Refer to Create custom Scan Engine definitions for details.
- In addition to those fields, when viewing an existing definition, you will also see Override. To modify a base system definition, use the override field to disable it and create a new custom definition. The definition is overridden to create the current definition.
This field is only visible if a base definition has been overridden using Override Definition. Deleting an overridden definition re-enables the base system definition.
Note: Overridden definitions are considered custom definitions. As a result, they are included in the count of 10 active custom definitions limit for Guided customers.
Select Update.
Selecting Delete will delete the override, meaning the base system definition will be used going forward.
Related lists appear at the bottom of the definition screen.
| Applicable Tables | Displays all tables scanned by the definition, as well as the conditions table records must match to be scanned.To add a table to the list:
See Restricted Caller Access for more information.
|
| Findings For This Definition | Displays any findings, as established by the definition, found during on-demand or scheduled scans. |
| Resolved Finding Histories | Shows findings that were resolved for this definition. |
| Scan Engine Suites | Displays all suites assigned to the definition, which allows for scanning entire suites of definitions. Suites are also used in reporting within the Analytics Dashboard. For more information, see Customize Scan Engine definition suites. To assign suites to a definition:
|