Managing Findings
  • 24 Nov 2024
  • 3 Minutes to read
  • Dark
    Light
  • PDF

Managing Findings

  • Dark
    Light
  • PDF

Article summary

Viewing the Custom Finding Configuration

You can click any Custom Finding in the Findings table to view its configuration.

To view the Custom Finding configuration

  1. In the Findings table, click a Finding.

  2. In the Finding Info drawer that opens, in the header, click the Go to Finding PencilEditIcon icon. The Finding Configuration drawer opens displaying the Finding configuration.

Editing the Custom Finding Configuration

You can view or edit the configuration of a Custom Finding in the Findings table.

To edit the Custom Finding configuration

  1. In the Finding Configuration drawer, update fields and settings, as required. Refer to Creating a Finding for field and setting explanations. The Save Changes button becomes enabled.
  2. Modify the external notification or Remove the external notification, if required.
  3. Click Save Changes.
Note:
  • When you modify a Finding's configuration, it might begin triggering alerts on different assets than before.
    For example, when you configure the Finding with a different query.

  • When you pivot from the latest alert in the Alerts History tab to the list of assets that triggered the alert, it opens the list of assets resulting from the alert based on the original rule (i.e., before the rule was modified). This is because the asset list is based on a historical snapshot of the assets at the time of the alert .

Modifying the External Notification

In a Custom Finding, you can choose an alternate enforcement action for an external notification or modify the configuration of the existing one.

To modify the external notification

  1. Hover over the defined external notification, and click the ChangeStatusIcon Edit icon that appears (see figure below).
  2. Modify the configuration of the external notification, by doing one of the following:
    • In Select Action, choose another enforcement action and fill in the required fields.
    • Modify the configuration of the current enforcement action.
  3. Click Apply.

Removing the External Notification

You can remove an external notification from a Findings Custom rule.

To remove an external notification

  1. Hover over the defined external notification, and click the TrashcanIconBlackonWhite Trashcan icon that appears (see figure below). The external notification is removed.
  2. Click Apply. The external notification is removed from the Findings Notification Enforcements folder in the Enforcement Center.

ExternalNotificationsHover

Updating the Status of a Finding Alert

In the row of a Finding in the Findings table, you can manually change the status of its latest alert. Learn how to change the alert status.
You can also change the status of a Finding's alert in the Alerts History table - Status column.

Deleting Findings

From the Findings table, you can delete one or more Findings (Custom).

To delete one or more Findings

  1. In the Findings table, hover over a row of a single Finding, and then at the end of the row, click the Delete Rule TrashcanIconBlackonWhite icon, or select the checkboxes of one or more Findings, and then on the top right of the table, click the Delete Rule action.
    DeleteFindingConfirmation
  2. In the Delete Finding box, click Delete Finding. The selected Findings are totally removed from the system, they are deleted from the Findings table and Total decreases accordingly.

Deactivating Findings

You can deactivate one or more Custom Findings from the Findings table or deactivate a single Custom Finding from its configuration. A deactivated Finding stops running in the system, but keeps past alert data.

To deactivate a Finding from its configuration

  1. In the Findings table, click a Finding, and in the Finding Configuration drawer that opens, toggle off Activate (default).
  2. Click Save Changes. The Finding's Activity Status changes to Inactive.

To deactivate one or more Findings from the Findings table

  1. In theFindings table, hover over a row of a single Finding, and then at the end of the row, click the Delete Rule TrashcanIconBlackonWhite icon, or select the checkboxes of one or more Findings, and then on the top right of the table, click the Delete Rule action.
  2. In the Delete Finding box that opens (see above), click Deactivate Finding. The Finding's Activity Status changes to Inactive.

Activating a Finding

A rule runs only while it is activated. You can activate a single Custom Finding from its configuration.

To activate a Finding

  1. In the Findings table, click a Finding, and in the Finding Configuration drawer that opens, toggle on Activate (default).
  2. Click Save Changes. The Finding's Activity Status changes to Active.


Was this article helpful?