---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuring auto-delete rules

# Configuring auto-delete rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

By configuring auto-delete rules, you can automate the process of deleting older findings and remediation tasks.

The base system provides two preconfigured auto-delete
rules that automatically remove closed records and any related records. One rule targets findings, and the other targets remediation tasks. These rules are inactive by default, so you must activate them
manually before they can delete any records. You can use the two preconfigured rules or create your own to suit your specific needs.

Configuration of auto-delete rules includes the following steps.
**Related concepts**   

* [Deleting stale findings automatically using auto-delete rules](https://servicenow-prod.fluidtopics.net/jAOTJDHJi5f8lDHNNV3~ug "Auto-delete rules automatically remove findings from the system based on predefined criteria. These rules help manage the life-cycle of vulnerabilities by ensuring that resolved or outdated findings are removed, reducing clutter and maintaining a clean, up-to-date database. This automation streamlines the vulnerability management process and ensures that teams focus on current and relevant issues.")

## Create or edit auto-delete rules {#ariaid-title2}

Create rules to delete findings and remediation tasks automatically based on specific filter conditions. These rules help remove older records from the Findings and Remediation Task tables.

### Before you begin

Role required: See [Access control lists (ACLs) for administration rules](https://servicenow-prod.fluidtopics.net/i0KpEC0Q1uMFl7DYVtZUsQ "You can either view or modify the administration rules based on the roles assigned to you.")

### Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. Select Administration in the navigation pane.
3. Select Review on the Auto delete rules tile.
4. On the Rules page, select Auto delete in the navigation pane.
5. Select New and fill in the fields on the form:  
   {#sem-create-edit-auto-delete-rules__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | Details ||
   | Tablename | Name of the table for which the rule is being applied. |
   | Matchfield | Field for which the system monitors the duration. |
   | Age in seconds | Age of the vulnerability record to be deleted. For both findings and remediation task rules, the age is 365 days. This age is displayed in seconds. |
   | Active | Indicates whether the rule is active. |
   | Cascade delete | Option to delete all matching records, plus any records referring to them. If this option isn't selected, only matching records are deleted, but not the records that refer to them. |
   | Conditions ||
   | Condition fields | Filter conditions defining the records in the Findings and Remediation Task tables to which the rules apply. |
   | New condition set | Adds more condition filter fields to choose from. |
   [Table 1. Auto-delete rule form]

   {#sem-create-edit-auto-delete-rules__table_vks_thr_ns}
6. Select Set conditions.
7. Select the conditions.
8. Select Set.
9. Select Save.  
   Once the rule is activated, the hourly platform function, Auto flush deletes those records from the table for which the rule is activated.

   If your environment contains millions of records
   that match your delete criteria, it's advisable to consult with ServiceNow Customer Support before enabling the auto-delete rules. They can assist you in deleting records through a phased process to ensure smooth and efficient data
   management.
{#sem-create-edit-auto-delete-rules__steps_ush_xnz_nfc}

*[\>]: and then


