Patch Management Single Rule Evaluator for 6.x and rule data gathering.

Article:HOWTO9061  |  Created: 2008-06-10  |  Updated: 2012-12-06  |  Article URL http://www.symantec.com/docs/HOWTO9061
Article Type
How To

Product(s)


Question
What is the Patch Management Single Rule Evaluator for 6.x and how do I use it?

Answer
 

The Patch Management 6.2 Single Rule Evaluator: To be ran on a client machine and will evaluate the Patch Management IsInstalled or ISApplicable rules.  To use the evaluator you need to follow these steps.

  1. Download the Patch Management Solution 6.2 Single Rule Evaluator (link is available on the right side panel and here  Test_Single_Inventory_Rule_6_2.zip).
  2. Copy the Single Rule Evaluator to the client computer
     
  3. Enable Verbose Logging on the Client manually by adding the following registry values to the computer or by saving the attached file Enable Patch Agent Verbose Logging_reg.txt as 'Enable Patch Agent Verbose Logging.REG' and double-click on it to import the necessary registry changes (Note: changes to these registry keys for PM 7.X and PM 7.1 SP1).
  • HKEY_LOCAL_MACHINE\SOFTWARE\ALTIRIS\EXPRESS\EVENT LOGGING\LOGFILE
    • Add a new DWord named Severity with value hexadecimal FF (decimal 255)
  • HKEY_LOCAL_MACHINE\SOFTWARE\ALTIRIS\ALTIRIS AGENT\INVENTORYRULEAGENT
    • Add a new DWord named VerboseLogging with value 8.
  1. Open Single Rule Evaluator and paste the IsApplicable Rule for the Security Update that you would like to evaluate. If you are unsure where to get the rule view article HOWTO2123.
  2. Click the Click Me button as seen in this example:
  3. Immediately go to the Installed Drive: > Program Files > Altiris > Altiris Agent  on the client, and right click the Log folder - Send to Compressed, for this will capture the Verbose Logging.
  4. Repeat Steps 4-6 for any other rules needed. Note: Once the Log file is compressed, rename it to reflect the update KB number with a - True/False, depending on what the GUI results shown.
    The results will display in two ways. On the UI, you will simply see a Rule Evaluation: true or false. 
    • True indicates the update is installed
       
    • False indicates the update needs to be installed.

      Note: If this is being run as a request from support, please drill down on the Client Machine to C:\Program Files\Altiris\Altiris Agent\Logs, right-click / Send To - Compressed, for the entire Log file is needed to view where the rule is failing.

      Note! This is an unsupported tool and is intended to be used only as a resource.

  5. Be sure to gather the following for Development Review:
    • PMImport version
    • Client's Add/Remove
    • Client's Registry Info 
      • The attached RegKey & Add-Remove.bat file can be ran on the client to easily gather these last two requirements of data.



Patch Management 7.x and 7.1 SP1 - Registry Locations:

Severity will be enabled at: HKEY_LOCAL_MACHINE\SOFTWARE\ALTIRIS\ALTIRIS AGENT\EVENT LOGGING\LOGFILE

  • Add a new DWord named Severity with value hexadecimal FF (decimal 255)

VerboseLogging will be enabled at: HKEY_LOCAL_MACHINE\SOFTWARE\ALTIRIS\ALTIRIS AGENT\INVENTORYRULEAGENT

  • Add a new DWord named VerboseLogging with value 8.

Advisory: this tool is not functional for Patch Management 7.1 SP1, for the updated product uses different IsApplicable / IsInstalled Rules. However, the verbose logging is helpful when running scans.

 

 


Attachments

Test Single Inventory Rule_6_2.zip (761 Bytes)
Enable Patch Agent Verbose Logging_reg.txt (488 Bytes)


Simple script to run on the client. CMD prompt will open to display what data is being pulled into the txt doc. Provide Text doc to satisfy the last 2 data requests, along with the Rule Return screen shot and logs.
RegKey & Add-Remove.bat (3 kBytes)

Legacy ID



42072


Article URL http://www.symantec.com/docs/HOWTO9061


Terms of use for this information are found in Legal Notices