Reconcile unmatched discovered items
Create a scheduled job to reconcile unmatched discovered items.
Before you begin
Roles required: admin
About this task
A vulnerable item (VI) consists of a vulnerability and a configuration item (CI). When a VI is created, the CI that is added to it at the time of creation might be an outdated one. Unmatched CI information is not reconciled if the information in the CMDB changes. To reconcile, apply configuration Item (CI) lookup rules on the items that are in an unmatched state when the CMDB is updated with the latest CIs.
You can run a scheduled job demand to reapply the CI matching rule for the discovered items in an unmatched state. If the CI changes after reapplying the lookup rules, the discovered items are updated with the new CI. Impacted detections and vulnerable items are also updated. For details, see CI changes for discovered items.
Procedure
Navigate to All > Security Operations > Reconcile Unmatched Discovered Items.
On the Background Jobs page, click Create reconciliation job.
On the form, fill in the fields.
Note: You can only edit the Parameters field.
| Field | Description |
|---|---|
| Number | Unique job number. |
| Created by | User who created the job. |
| Parameters | Parameters to reconcile the unmatched discovered items:- limit: Maximum number of discovered items to be reconciled. If you do not enter a value, 10,000 discovered items are reconciled. - firstDiscovereditem: First discovered item that must be reconciled. If you do not enter a value, the reconciliation process starts from the first discovered item. |
| State | Current state of the background job. |
| State description | Description of the current state of the background job. |
| Job type | Type of job. The value is Reconcile unmatched discovered items. |
| Started at | Time when the job started. |
| Ended at | Time when the job was completed. |
| Job duration | Total time taken to complete the job. |
| Substate | Substate for the selected state. |
| Notes | Number of records that were processed. |
Click Submit.
Note:
- To stop running the job, click Cancel.
- You can't reconcile unmatched CIs or reapply CI lookup rules while you are importing hosts or vulnerable items.
- Starting with Vulnerability Response v26.0.11, you can "Reapply Look up Rules" for selected or filtered items in the discovered items table view.
Note: From the above mentioned version, the reconcile unmatched discovered items scheduled job is retired.
Select All > Security Operations >Reapply Look up Rules for selected or filtered items in the discovered items table.
Note: If no filter is applied, the reapply option will be disabled.
After reapplying, a background job URL or an error message will pop-up, once the integration is running.
Reapply CI lookup rules on selected discovered items
Reapply the configuration item (CI) lookup rules on selected discovered items from the discovered item list view select actions. If the CI changes after you reapply the rules, the discovered items are updated with the new CI and impacted detections. Vulnerable items are also updated.- Reapply CI Lookup Rules Enhancements
Reapply the configuration item (CI) lookup rules on selected discovered items like os and netbios.
Parent Topic:Working with unmatched CIs
Related topics
View and reclassify unmatched configuration items