Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View Configuration Compliance test results

View Configuration Compliance test results for auditing and remediation. The test results are automatically created during third-party vulnerability integration imports.

Important: You can view the test results created during the third-party vulnerability integration imports in the Vulnerability Manager Workspace. For more information, see List page in the Vulnerability Manager Workspace.

Before you begin

Role required:

  • sn_vulc.read to view
  • sn_vulc.remediation_owner to view and update
  • sn_vulc.delete to delete

About this task

Configuration Compliance does not create or update the test results, but imports them as part of a third-party integration. Once they are viewable in Configuration Compliance, they are remediated using Test Result Groups.

Note: Starting with v14.9 of Configuration Compliance, the following terms have been renamed:

Terminology prior to v14.9Terminology v14.9 onwards
Test Result GroupRemediation Task
Group RulesRemediation Task Rules
PolicyTest group

Procedure

  1. Navigate to All > Configuration Compliance > Test Results.

    Starting with v15.0 of Configuration Compliance, the following columns appear in the Test Results list.

ColumnDescription
ActiveIndicates if a test result is active. A test result is marked:- True: If the State isn’t Closed. - False: If the State is Closed.
AgeTime period for which a test result is active since it was last open.This field is empty for a closed test result. Format: Days HH:MM: SS For more information on how to customize the Age calculation, see the KB1703270 article.
Age closedTime period for which a test result was active before it transitioned to ‘Closed'. When the test result transitions to ‘Closed', the value from the Age column is displayed in the Aged closed field. This field is empty for an active test result. Format: Days HH:MM: SS For more information on how to customize the Age closed calculation, see the KB1703270 article.
ClosedTimestamp at which a test result is closed.Format: YYYY-MM-DD HH:MM: SS
Last openedTimestamp at which a test result is opened, that is, when the Active field value changes to true.
  1. Open the control that you want to view.
FieldDescription
NumberThe number assigned to the test during the import process.
SourceThe system name of the third-party SCA application, or the name entered in the application plugin for the API that is used to communicate with Configuration Compliance.
Source IDThe identifier assigned to the control by the SCA application.
ResultPassed, Failed, Error, or Unknown. Imported from Qualys.
Risk scoreCalculator result for this test.Prior to v15.0 of Configuration Compliance, the risk score of a passed test result is set to '0'. Starting with v15.0 of Configuration Compliance, the risk score of the passed test result isn’t changed to '0' so that you can estimate the risk mitigated. The risk score of the passed test result isn’t included in calculating the risk score of a remediation task.
Risk ratingBased on a range of risk scores on a 1-5 numeric scale that rates overall risk based on a range of risk scores as 1 - Critical to 5 - None. This field replaces the Priority field in previous versions.
StateCalculated from the remediation tasks that the test result belongs to. If the test result belongs to multiple groups, an order of precedence is applied to determine state.
ResolutionCalculated from the remediation tasks that the test result belongs to. If the test result belongs to multiple groups, an order of precedence is applied to determine resolution.
First seenDate first imported into Configuration Compliance.Starting with v13.1.1, the First seen field displays the date provided by the scanner. Otherwise, it displays the date first imported into Configuration Compliance.
Last seenDate last imported into Configuration Compliance.Starting with v13.1.1, the Last seen field displays the date provided by the scanner. Otherwise, it displays the date last imported into Configuration Compliance.
Last passLatest date on which the test result is passed.
TestName of the test.
Configuration itemName of the CI attached to the test.
TechnologySoftware version running on the CI.
DescriptionDescription of the test
Expected ValuesExpected values configured in Qualys and imported by Configuration Compliance. This value is a Boolean expression that when evaluated to true makes the test result Passed. The expression can be a combination of logical, set, or regular expression operators.
Actual ValuesValues returned by the test. These values are plugged into the expected values Boolean expression to determine if the result should pass or fail. They’re imported from Qualys.Starting with version 14.9 of Configuration Compliance, the Extended Evidence and Cause of Failure values are added in the Actual Values column.
RemediationRemediation instructions.
Related Tabs
Remediation TasksRemediation tasks associated with this test result.
Test Result HistoryRelated list of test results that show the history of pass/fail results for the same CI/technology/test.