Installation guide

Table Of Contents
Procedure
1. "Generate a Patch Assessment Template" on page 171
To configure VCM for automatic, event-driven patch deployment, you must generate a patch
assessment template to use with the automatic patch deployment mapping.
2. "Run a Patch Assessment on Managed Machines" on page 172
You must run the patch assessment template to collect patch status data from the managed machines.
3. "Add Exceptions for Patching Managed Machines" on page 172
You can optionally add patching exceptions for the automatic patch deployment.
4. "Configure the VCMAdministration Settings" on page 173
VCM provides settings for automatic patch deployment, including template and group membership,
patch applicability, and default threshold data age. You can set the default repository host, repository
path, and Software Content Repository (SCR) Tool base path settings.
5. "Generate a Patch Deployment Mapping" on page 175
VCM provides settings for automatic patch deployment, including template and group membership,
patch applicability, and default threshold data age. You can set the default repository host, repository
path, and Software Content Repository (SCR) Tool base path settings.
What to do next
n
For Linux and UNIX patching, after a job triggers, view the job chain in the VCM Job Manager, and
finished job chain jobs in Job Manager History. See "How the Linux and UNIX Patching Job Chain
Works" on page 178.
n
(Optional) You can schedule an automatic patch deployment. When you schedule VCM to run an
automatic patch deployment later, and collected patch data or scheduled the patch data collection after
you created the automatic deployment but before the scheduled time to run the automatic deployment.
VCM begins the automatic patch deployment at the scheduled time. See "Configure VCM for
Automatic Scheduled Patch Assessment and Deployment" on page 176.
Generate a Patch Assessment Template
To configure VCM for automatic, event-driven patch deployment, you must generate a patch assessment
template to use with the automatic patch deployment mapping. VCM uses the patch assessment template
to collect patch assessment data from Linux, UNIX, or Windows managed machines in your environment.
With automatic, event-driven patch deployment, you configure a patch assessment template with a
machine group, and VCM deploys patches to the Linux, UNIX, or Windows patching assessment template
that you associate with the machine group.
To create a dynamic membership of bulletins for the Linux and UNIX patch assessment, you can use
dynamic patching assessment templates to apply filter criteria. After new patch content is available, VCM
updates the bulletin membership of a dynamic assessment template. To exclude certain patches from
being applied to a specific set of managed machines or from all managed machines in your environment,
you can create patching exceptions for dynamic and static patching assessment templates.
Prerequisites
Review the steps to configure the automatic, event-driven patch assessment and deployment. See
"Configure VCMfor Automatic Event-Driven Patch Assessment and Deployment" on page 170.
Patching Managed Machines
VMware, Inc.
171