---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring auto-close rules

# Configuring auto-close rules {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

By configuring auto-close rules, you can automate the process of closing stale detections and findings associated with retired configuration items (CIs).  
The base system provides the following auto-close rules:

* Assets last scanned: Detections associated with assets that haven't been scanned within the last 90 days are transitioned to Stale state.
* Detections last found: Detections that haven't been found within the last 90 days. If you activate Detections last found record, then this feature requires a successful integration run of Rapid7 Comprehensive Vulnerable Item Integrations and Microsoft TVM Machine Vulnerabilities Integration (Full import) within the last seven days.
{#sem-configure-auto-close-rules__create-auto-close-rules_ul_ugw_flv_hbc}

Configuration of auto-delete rules includes the following steps.
**Conceitos relacionados**   

* [Closing stale detections and findings automatically using auto-close rules](https://servicenow-prod.fluidtopics.net/8raii9R3RjBxGlwfZDkT0w "Auto-close rules automatically close stale detections and findings based on predefined criteria. These rules ensure that redundant or unwanted findings are marked as closed, helping to maintain an accurate and up-to-date record of the organization's security posture. By automating this process, the rules reduce manual effort and enable teams to focus on active and critical vulnerabilities.")

## Create or edit auto-close rules {#ariaid-title2}

Create rules to close stale detections and findings associated with retired CIs automatically.

### Antes de Iniciar

Role required: See [Access control lists (ACLs) for administration rules](https://servicenow-prod.fluidtopics.net/OOZfh~3y7q7~R6CPggT5cg "You can either view or modify the administration rules based on the roles assigned to you.")

### Procedimento

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. Select Administration in the navigation pane.
3. Select Review on the Auto-close rules tile.
4. On the Rules page, select Auto-close in the navigation pane.
5. Select New and fill in the fields on the form:  
   {#sem-create-edit-auto-close-rules__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Details ||
   | Name | Name of the rule. |
   | Table | Name of the finding type for which the rule is being applied. Nota: For vulnerable items (VITs), rules are applied to detections first, and then applied to the VITs, rather than being directly applied to the VITs. |
   | Description | Description of the rule. |
   | Active | Indicates whether the rule is active. |
   | If this condition is met ||
   | Condition fields | Filter conditions defining the records in the Findings and Remediation Task tables to which the rules apply. |
   | New condition set | Adds more condition filter fields to choose from. |
   | Then do this ||
   | Close findings automatically |   |
   | Ignored deferred items | If selected, any findings or detections that are mapped to the In-review or Deferred states are ignored and not closed. If you clear this option, any findings or detections that match your criteria are closed. |
   [Tabela 1. Auto-close rule form]

   {#sem-create-edit-auto-close-rules__table_vks_thr_ns}
6. Select Save.  
   The Auto-Close Stale Detections scheduled job runs daily. It identifies detections based on the specified conditions and transitions the matching ones to the Stale
   state.

   The job handles the following scenarios:
   * If all the detections within a VIT are marked as stale, the VIT is closed with the sub-state set as "Stale".
   * If there is at least one detection that remains open within a VIT, while others are in the Stale status, the VIT remains open.
   * In cases where there are detections with both "Closed" and "Stale" statuses within a VIT, the VIT is closed with the sub-state set as "Fixed".

   {#sem-create-edit-auto-close-rules__create-auto-close-rules_ul_iy4_1nv_hbc}

   When you upgrade to the latest version of Unified Security Exposure Management, the conditions set in your auto-close rules also get updated accordingly. Additionally, if the rules are associated with different domains, the rules are created specifically
   within those domains.
{#sem-create-edit-auto-close-rules__steps_ush_xnz_nfc}

