90 lines
4.0 KiB
Markdown
90 lines
4.0 KiB
Markdown
|
|
# Ivanti Queue & Batch Operations Guide
|
||
|
|
|
||
|
|
## Overview
|
||
|
|
|
||
|
|
The Ivanti Queue is a personal staging area for batch-processing vulnerability findings. You select findings from the Reporting Page table, assign them a workflow type and vendor, and stage them in the queue. From there you can create FP workflows, track Archer exceptions, or manage CARD dispositions.
|
||
|
|
|
||
|
|
## Workflow Types
|
||
|
|
|
||
|
|
| Type | Color | Purpose | Vendor Required? |
|
||
|
|
|------|-------|---------|-----------------|
|
||
|
|
| FP | Amber | False Positive — finding is not actually a vulnerability | Yes |
|
||
|
|
| Archer | Blue | Risk Acceptance — vulnerability exists but can't be patched | Yes |
|
||
|
|
| CARD | Green | Asset disposition — device not owned by your BU | No |
|
||
|
|
|
||
|
|
## Adding Findings to the Queue
|
||
|
|
|
||
|
|
### Single Finding
|
||
|
|
1. In the findings table, click the checkbox area on a row (not the checkbox itself — click the cell)
|
||
|
|
2. A popover appears with:
|
||
|
|
- The finding ID
|
||
|
|
- Vendor/Platform input field (required for FP and Archer)
|
||
|
|
- Workflow type toggle (FP / Archer / CARD)
|
||
|
|
3. Enter the vendor name and select the workflow type
|
||
|
|
4. Click "Add to Queue"
|
||
|
|
|
||
|
|
### Batch Add (Multiple Findings)
|
||
|
|
1. Select multiple findings using checkboxes (Shift+Click for range selection)
|
||
|
|
2. The selection toolbar appears at the top of the table
|
||
|
|
3. Choose the workflow type (FP / Archer / CARD)
|
||
|
|
4. Enter the vendor name (not needed for CARD)
|
||
|
|
5. Click "Add to Queue" — all selected findings are added at once (up to 200 per batch)
|
||
|
|
|
||
|
|
## The Queue Panel
|
||
|
|
|
||
|
|
Click the **Queue** button (top right of the Reporting Page) to open the slide-out panel. The badge shows the count of pending items.
|
||
|
|
|
||
|
|
### Layout
|
||
|
|
- Items are grouped by vendor (alphabetically)
|
||
|
|
- CARD items appear in their own green section at the top
|
||
|
|
- Each item shows: finding ID, CVEs, hostname, IP address, and workflow type badge
|
||
|
|
|
||
|
|
### Item Actions
|
||
|
|
|
||
|
|
| Action | How |
|
||
|
|
|--------|-----|
|
||
|
|
| Mark complete | Click the green checkbox |
|
||
|
|
| Mark pending | Uncheck the green checkbox |
|
||
|
|
| Select for deletion | Click the red checkbox (left side) |
|
||
|
|
| Delete selected | Click "Delete (N)" button in footer |
|
||
|
|
| Clear all completed | Click "Clear Completed" button in footer |
|
||
|
|
| Redirect workflow | Click the redirect arrow (↗) on completed items |
|
||
|
|
|
||
|
|
### Redirect Feature
|
||
|
|
|
||
|
|
When a finding is completed under one workflow type but needs to be processed under another:
|
||
|
|
1. Complete the item first
|
||
|
|
2. Click the redirect arrow (↗) icon
|
||
|
|
3. Choose the new workflow type
|
||
|
|
4. A new pending item is created with the same finding data but the new workflow type
|
||
|
|
|
||
|
|
Example: You submitted an FP but it was rejected. You now need to open an Archer ticket instead. Complete the FP item, then redirect it to Archer.
|
||
|
|
|
||
|
|
## Creating FP Workflows from the Queue
|
||
|
|
|
||
|
|
1. Open the Queue panel
|
||
|
|
2. Select pending FP items using the checkboxes
|
||
|
|
3. Click "Create FP Workflow" in the footer (only enabled when FP items are selected)
|
||
|
|
4. Fill in the workflow details (name, reason, description, expiration date)
|
||
|
|
5. Attach supporting files (screenshots, evidence)
|
||
|
|
6. Submit — the workflow is created in Ivanti and queue items are marked complete
|
||
|
|
|
||
|
|
See the [FP Submission Editing Guide](kb-fp-submission-editing-guide.md) for details on editing submitted workflows.
|
||
|
|
|
||
|
|
## FP Submissions Section
|
||
|
|
|
||
|
|
Below the queue items, a "Submissions" section shows your previously submitted FP workflows with:
|
||
|
|
- Workflow name and Ivanti batch ID
|
||
|
|
- Lifecycle status badge (Submitted, Rework, Rejected, Resubmitted, Approved)
|
||
|
|
- Finding count and submission date
|
||
|
|
|
||
|
|
Click any submission to open the Edit Modal for viewing details, adding findings, or reading reviewer notes.
|
||
|
|
|
||
|
|
## Tips
|
||
|
|
|
||
|
|
- Group related findings by vendor before adding to the queue — this makes it easier to create batch FP workflows
|
||
|
|
- Use CARD for findings on devices that belong to another team — no vendor entry needed
|
||
|
|
- The queue is per-user — other team members can't see or modify your queue items
|
||
|
|
- Completed items stay in the queue until you clear them, so you have a record of what was processed
|
||
|
|
- Use the redirect feature when a workflow type needs to change after initial processing
|