VRM Applications and Dashboards
use this reference to identify where vrm stores operational records, supporting workflow data, and reporting views choose your path goal go to manage findings, assets, cases, remediation, or exceptions operational applications /#operational applications monitor ingestion, filtering, exports, or reporting data supporting applications /#supporting applications select an operational or reporting dashboard dashboards /#dashboards review workspaces, assets, sensors, and the packaged connector supporting solution content /#supporting solution content operational applications operational applications store the records analysts use to prioritize, investigate, group, remediate, and close vulnerability work vulnerability finding acronym vfin the vulnerability finding application is the primary system of record for vulnerabilities each record represents a vulnerability associated with one asset information group examples identification vulnerability id, source, scan id, unique id, and raw finding data asset context asset reference, primary identifier, hostnames, ip addresses, mac addresses, zone, criticality, and additional metadata risk and intelligence turbine risk score, cvss, epss, exploit data, known exploitation, weaknesses, attack patterns, and mitre att\&ck techniques case and exception state grouping id, grouping status, case tracking id, and exception reference remediation status, remediation owner, remediation advice, sla status, outcome, and dates automation health requires attention and supporting documentation use this application to prioritize findings by turbine risk score review vulnerability and asset context reassign an asset when the existing association is incorrect reprocess a finding through enrichment and scoring add findings to a case or create a manual case review exception and remediation status see vulnerability findings docid\ zxxjro6dhpdfa9otysq0 for the published finding details vulnerability asset acronym vast the vulnerability asset application stores systems associated with vulnerability findings information group examples identity primary asset identifier, asset type, hostnames, ip addresses, mac addresses, and repositories business context asset zone, zone criticality, asset criticality, and additional metadata risk asset risk score, score label, highest risk finding, open finding count, and last update time remediation routing remediation owner, remediation channel, and risk based sla targets automation health requires attention and supporting documentation changes to asset criticality, zone, owner, or remediation channel can propagate to associated open findings see vulnerability asset management docid 2bkjktmgdn6ivcptinpgq for the published asset details vulnerability case management acronym vrsp the vulnerability case management application groups related findings into an analyst owned unit of work use a case to review all grouped findings track the current owner and case owner prioritize work by the highest associated turbine risk score create remediation items monitor remediation creation status and automation errors close the case after associated findings are resolved cases can be created manually, through automated grouping, or through automated grouping and remediation see vulnerability case management docid\ xu7asa7xgljyn xte5vk for the published case details vulnerability remediation item acronym vri the vulnerability remediation item application tracks remediation work for one case and its associated findings key information includes case tracking id finding tracking ids and summaries remediation owner and channel external ticket id and url ticket status, message, and last update time requires attention and supporting documentation depending on solution configuration, vrm can submit a remediation item automatically or wait for a user to initiate create itsm ticket see creating and managing remediation items docid\ oktubygx22ptkmv8g8nzv for the published remediation workflow vulnerability exception acronym vexc the vulnerability exception application defines findings that do not require standard remediation an exception can use criteria such as vulnerability identifiers asset identifiers or zones finding sources minimum and maximum turbine risk score effective and expiration dates enabled or disabled status the exception workflow evaluates matching criteria during finding enrichment applicable findings receive the exception state and can be excluded from normal remediation and sla calculations see exception management docid 0c cv6s6g34j0 7jmi5m for the published exception details supporting applications application acronym purpose vrm csv import vci stores finding or asset csv attachments, source selection, page size, import state, and row counts vrm ingestion page vmip stores one batch of finding data, its attachment, source, count, processing status, sample data, and error details vrm export results ver stores known finding exports used by deduplication, including current or stale state, row count, file, and processing time vrm filtering activity vfa stores filtering and deduplication metrics, including excluded, known, and unseen findings, memory use, and runtime vrm reporting vrpt stores metric snapshots for findings, assets, exceptions, and remediation items used by the reporting dashboard supporting applications are primarily maintained by automation use them to monitor processing, investigate failures, and validate reporting inputs application relationships source related application relationship vulnerability finding vulnerability asset a finding references the affected asset and copies selected asset context for scoring and routing vulnerability finding vulnerability exception a finding references an applicable active exception vulnerability finding vulnerability case management grouped findings store the case tracking id and contribute to case risk vulnerability case management vulnerability remediation item a case creates one or more remediation items based on grouped findings and routing information vulnerability remediation item finding and case records ticket state propagates to associated findings and the parent case csv import ingestion page a finding csv is divided into page records before filtering and enrichment export results filtering activity the current known finding export supports comparison; filtering records capture the outcome operational applications vrm reporting scheduled reporting flows aggregate operational data into metric records application automation map use this map to identify the automation that creates or updates each primary record and where to verify the result application created or updated by related records verify vulnerability finding enrichment pipeline , re enrich finding , asset updates, exception processing, grouping, and ticket status synchronization vulnerability asset, vulnerability exception, vulnerability case management, and vulnerability remediation item risk score, asset association, exception state, grouping status, case tracking id, remediation status, and requires attention vulnerability asset write assets , calculate asset risk scores , and asset metadata refresh open vulnerability finding records associated by asset identifiers asset identifiers, criticality, owner, remediation channel, aggregate risk, open finding count, and requires attention vulnerability case management case creation , create new case , case risk score updates, and remediation status synchronization grouped vulnerability finding records and created vulnerability remediation item records finding relationships, owner, highest risk score, remediation state, and requires attention vulnerability remediation item create remediation items , ticket submission, ticket status checks, and ticket closure parent vulnerability case management record, grouped findings, and external itsm ticket owner, channel, ticket id and url, ticket status, last update time, and requires attention vulnerability exception administrator managed exception records evaluated during finding enrichment and re enrichment matching vulnerability finding records enabled state, matching criteria, effective dates, expiration date, and affected findings dashboards dashboard use vulnerability management overview review active findings, assets, critical assets, case counts, exceptions, sla status, risk distribution, and remediation performance assets overview review asset inventory, risk, criticality, highest risk findings, and remediation ownership vulnerability analyst view prioritize analyst work across findings and cases by risk, status, owner, and other operational filters requires attention view locate assets, findings, cases, and remediation items that require configuration or manual intervention vrm reporting review historical and aggregate reporting records generated for findings, assets, exceptions, and remediation items vrm utilities dashboard monitor ingestion volume, page queues, filtering, enrichment progress, and source distribution dashboard reports and counts can vary after administrators customize the solution supporting solution content supporting content connects application workflows, stores required configuration, and organizes operational views workspaces workspace purpose vrm vulnerability response management organizes the main operational applications and dashboards vrm utilities organizes csv ingestion, ingestion pages, exports, filtering activity, and utility monitoring custom assets asset parameters use turbine tenant credentials host, account id, tenant id, personal access token allows packaged automation, including the reporting playbook, to access tenant data treat personal access tokens as secrets do not place token values in documentation, exported examples, or unprotected records sensors sensor type use write assets page flow event submits an array of normalized asset objects for writing write ingestion page flow event creates one file backed ingestion page submit ingestion page to enrichment pipeline flow event passes a queued ingestion page to normalization and enrichment vulnerability finding flow event submits a finding to the standard enrichment pipeline close vulnerability finding flow event submits a finding for closure processing packaged connector to ingest qualys vulnerability data, install and configure the supported qualys vulnerability scanner connector and its required asset use the connector documentation for available actions and configuration requirements next steps review vulnerability response management workflows docid\ ny3lbmo1jcrpu3okyizox to follow data between applications review vrm playbooks and components docid c4ksjvnm0ixzzecpx4yq to identify the automation that maintains each record type