5.8
Table Of Contents
- VMware vRealize Configuration ManagerAdministration Guide
- Contents
- About This Book
- Getting Started with VCM
- Installing and Getting Started with VCM Tools
- Configuring VMware Cloud Infrastructure
- Virtual Environments Configuration
- Configure Virtual Environments Collections
- Configure Managing Agent Machines for Virtual Environment Management
- Obtain the SSL Certificate Thumbprint
- Configure vCenter Server Data Collections
- Configure vCenter Server Virtual Machine Collections
- Configure vCloud Director Collections
- Configure vCloud Director vApp Virtual Machines Collections
- Configure vShield Manager Collections
- Configure ESX Service Console OS Collections
- Configure the vSphere Client VCM Plug-In
- Running Compliance for the VMware Cloud Infrastructure
- Create and Run Virtual Environment Compliance Templates
- Create Virtual Environment Compliance Rule Groups
- Create and Test Virtual Environment Compliance Rules
- Create and Test Virtual Environment Compliance Filters
- Preview Virtual Environment Compliance Rule Groups
- Create Virtual Environment Compliance Templates
- Run Virtual Environment Compliance Templates
- Create Virtual Environment Compliance Exceptions
- Resolve Noncompliant Virtual Environments Template Results
- Configure Alerts and Schedule Virtual Environment Compliance Runs
- Configuring vCenter Operations Manager Integration
- Auditing Security Changes in Your Environment
- Configuring Windows Machines
- Configure Windows Machines
- Windows Collection Results
- Getting Started with Windows Custom Information
- Prerequisites to Collect Windows Custom Information
- Using PowerShell Scripts for WCI Collections
- Windows Custom Information Change Management
- Collecting Windows Custom Information
- Create Your Own WCI PowerShell Collection Script
- Verify that Your Custom PowerShell Script is Valid
- Install PowerShell
- Collect Windows Custom Information Data
- Run the Script-Based Collection Filter
- View Windows Custom Information Job Status Details
- Windows Custom Information Collection Results
- Run Windows Custom Information Reports
- Troubleshooting Custom PowerShell Scripts
- Configuring Linux, UNIX, and Mac OS X Machines
- Linux, UNIX, and Mac OS X Machine Management
- Linux, UNIX, or Mac OS X Installation Credentials
- Configure Collections from Linux, UNIX, and Mac OS X Machines
- Configure Installation Delegate Machines to Install Linux, UNIX, and Mac OS X...
- Configure the HTTPS Bypass Setting for Linux Agent Installations
- Enable Linux, UNIX, and Mac OS X Agent Installation
- Add and License Linux, UNIX, and Mac OS X Machines for Agent Installation
- Install the VCM Agent on Linux, UNIX, and Mac OS X Operating Systems
- Collect Linux, UNIX, and Mac OS X Data
- Linux, UNIX, and Mac OS X Collection Results
- Configure Scheduled Linux, UNIX, and Mac OS X Collections
- Using Linux and UNIX Custom Information Types
- File Types that VCM can Parse
- Parsers for Supported File Types
- Identification Expressions
- Parser Directives
- Parser Directives for Linux, UNIX, and Mac OS X
- Creating Custom Information Types for Linux and UNIX
- Custom Information Types for Linux, UNIX, and Mac OS X
- Add, Edit, or Clone Custom Information Types for Linux and UNIX
- UNIX Custom Information Data View in the Console
- Path Panel in the VCM Collection Filter
- Patching Managed Machines
- Patch Assessment and Deployment
- Prerequisite Tasks and Requirements
- Manually Patching Managed Machines
- Getting Started with VCM Manual Patching
- Configuring An Automated Patch Deployment Environment
- Deploying Patches with Automated Patch Assessment and Deployment
- Configure VCM for Automatic Event-Driven Patch Assessment and Deployment
- Generate a Patch Assessment Template
- Run a Patch Assessment on Managed Machines
- Add Exceptions for Patching Managed Machines
- Configure the VCM Administration Settings
- Generate a Patch Deployment Mapping
- Configure VCM for Automatic Scheduled Patch Assessment and Deployment
- How the Linux and UNIX Patch Staging Works
- How the Linux and UNIX Patching Job Chain Works
- How the Deploy Action Works
- Patch Deployment Wizards
- Running Patching Reports
- Running and Enforcing Compliance
- Configuring Active Directory Environments
- Configuring Remote Machines
- Tracking Unmanaged Hardware and Software Asset Data
- Managing Changes with Service Desk Integration
- Index
Procedure
1. Copy the bundle ZIP file to the following folder.
\\machine-name\CMFiles$\SCAP\Import
2. Click Compliance.
3. Select SCAP Compliance > Benchmarks.
4. Click Import.
5. Highlight the bundle, and click the right arrow to select it for import.
6. Click Next.
7. Review your selections and click Finish.
Run an SCAP Assessment
Run an SCAP assessment that compares your managed machine configuration against a profile in a
standard SCAP benchmark.
Prerequisites
Import the benchmark. See "Import an SCAP Benchmark" on page 215.
Procedure
1. Click Compliance.
2. Select SCAP Compliance > Benchmarks > benchmark name > profile name.
3. Click Run Assessment.
4. Highlight the machines to assess, and click the down arrow to select them.
5. Click Next and click Next again.
6. Click Next, review your selections, and click Finish.
A collection job starts, and results are not available until the job finishes. The process differs from the
general VCM compliance feature, which looks at existing collection data in the database.
View SCAP Assessment Results
Open and search SCAP assessment results through access in the data grid for the profile against which you
measured managed machines.
Where appropriate, VCM includes the corresponding standard identifier in its SCAP assessment results
and provides an embedded hyperlink to information about the identifier on Web pages such as those
provided by MITRE.
Prerequisites
Generate an assessment. See "Run an SCAP Assessment" on page 216.
vRealize Configuration Manager Administration Guide
216
VMware, Inc.