Feb 15, 2022
03:58 PM
1 Kudo
Hi @durgeshsingh , the recommendation is to scan as less as possible and as much as necessary. Could you please describe the use case why you're using a full file scan? In our projects we have made the experience that especially in the non-Windows/Unix environment there are always special folders in which the administrators install the applications. You should limit the scan to these few folders. This reduces the cpu load per client and does not blow up the file evicence tables in FNMS. Best, Dennis
... View more
Dec 14, 2021
03:20 PM
3 Kudos
@joshstechnij, thanks for this update. Is there any way to disable this feature afterwards (e.g. Group Policy, Registry Update, ...). There is already an IDEA to control different agent functions afterwards in the FNMS UI. This would be another great feature if you could e.g. control the Docker services with appropriate targets
... View more
Dec 14, 2021
02:30 AM
3 Kudos
Hi @winvarma please have a look at this posting about the "FNMSPreCalcUpdate" Process in FNMS. https://community.flexera.com/t5/FlexNet-Manager-Knowledge-Base/FNMSPreCalcUpdate-Initial-Diagnosis/ta-p/154595 A solution can be, to add a Windows Task and trigger the FNMSPreCalcUpdate manualle every hour e.g. BatchProcessorTaskConsole.exe run FNMSPreCalcUpdate Best, Dennis
... View more
Dec 13, 2021
01:56 PM
4 Kudos
First own investigations have shown the following: FlexeNet Manager Suite - No, using log4net Cognos Analytics - Yes, log4j v1.2 - v2.x FlexNet FNMEA - yes (https://docs.flexera.com/fnmea/2020r1/InstallationGuide/Content/helplibrary/FlexNet_Log_Files.htm) But let's wait for some feedback from Flexera
... View more
Dec 13, 2021
01:53 PM
1 Kudo
Hi, Of course libraries can be recognized by their name, but there is also a considerable amount of components that are located directly in the *.jar file etc.. these data cannot be read by the agent. That's probably the next big challenge, but that's where I don't think the Flexera Agent can help
... View more
Dec 13, 2021
01:49 PM
1 Kudo
Personally, I think that the result of a full-file scan will not provide more information than, for example, a Windows search for "log4j*". Certainly many libraries can be recognized by their name, but there is also a considerable amount of components that are located directly in the *.jar file etc.. Of course, the agent cannot read this information. I would recommend in this case that an appropriate tool is used for dedicated detection, this information is certainly already available to most IT admins. Best, Dennis
... View more
Dec 13, 2021
07:09 AM
1 Kudo
Please have a look at this posting, it will be updated by Flexera https://community.flexera.com/t5/Community-Notices/Security-Advisory-Log4j-Java-Vulnerability-CVE-2021-44228/bc-p/217018#M86
... View more
Oct 12, 2021
07:26 AM
1 Kudo
Hi, With the use of Flexera Analytics and the dynamic management dashboard available since a few releases, a permanent export of the FNMS data to the DataWarehouse is necessary. This is realized by default via the "FNMPDataWarehouse" task and the associated partial export. Now our customer operates a very large environment (+300k inventories, +150k assets, +60k purchases, +5k licenses) - in which there are permanent changes to the data, which is also reflected in the long runtimes of the FNMSDataWarehouse task. Per run the task needs about 1.5h and afterwards the next one starts, again for a similar runtime. Except at night, when none works on the system, the runtimes are a few minutes. https://community.flexera.com/t5/FlexNet-Manager-Knowledge-Base/New-log-files-in-Compliance-Reader-importer-ConcurrentDashboard/ta-p/5755 Now there is the possibility to control this via registry for the runtime of the task. If we set the value "DashboardJobPollTimeSeconds" to 1h, then the system still starts with a partial export of the data and not only with the data collection, I would have expected this step only at the start of the timer "DashboardJobCooldownTimeSeconds". Can anyone say anything more specific about this. Due to the heavy load on the FNMS system caused by the Partial Export, we want to run it as infrequently as possible, but as often as necessary. What are the disadvantages for the dashboard and analytics if the task is executed only 2x days? Thanks and Best, Dennis
... View more
Sep 16, 2021
06:40 AM
2 Kudos
Hi @Ronny_OO7, with reference to the documentaion (https://docs.flexera.com/FlexNetManagerSuite2021R1/EN/WebHelp/index.html#topics/App-Devices_InvDev.html) it seems to be part of the Azure connector Inventoried cloud license model May show the kind of cloud licensing reported in inventory. In many cases, this value remains blank, and is only populated with a value for inventory devices that have been identified through the Azure connector, and only when you have configured the devices within Azure to take advantage of the Azure Hybrid Benefit. Best, Dennis
... View more
Sep 16, 2021
03:52 AM
2 Kudos
@AamerSharif based on the resolved issues. Is there any plan to integrate fix for IOJ-2198658 into the on-prem O365 adapter. Some times we run into this issue when gathering a huge amount of data from O365. IOJ-2198658 Integration: Other When the Microsoft 365 adapter runs more than an hour to collect the usage information, the import fails with an error - access token has expired Best, Dennis
... View more
Sep 13, 2021
07:17 AM
1 Kudo
Enclosed is an update and a note to adjust the Flexera documentation if necessary. As described in the documentation, it is recommended to take over the FNMS SAML settings from the web.config 1:1 ("Edit the web.config file using the same values noted in step 2 and 4 above.") . Unfortunately, according to our current experience, this is not quite correct. For each web application a separate IDP identityID must be requested, for this reason the simple transfer of the data leads to an error. Requesting a new entityID for the IDP and updating the config , solved the issue If your implementation uses Flexera Analytics, configure the separate web.config file for your Flexera Analytics server.
Flexera Analytics is visible by navigating to Reports > Analytics. If this is present:
- Switch to your Cognos server.
- Flexera Analytics (Cognos) is likely to reside on a separate server. For SAML-based single sign-on to work, the Cognos server and web application server must be in the same domain.
- In your flat text editor, open the local web.config file for the Cognos server.
- The default location (on Windows) is <drive>:\Program Files\ibm\cognos\analytics\cgi-bin.
- Edit the web.config file using the same values noted in step 2 and 4 above. @kent-au, @WheresThePizza or @ChrisG : Can you confirm this and do you think a change in the wording of the documentation is appropriate?
... View more
Sep 06, 2021
03:12 AM
1 Kudo
Hi, we have made small progress, but continue to have problems with SAML authentication. As described in the FNMS documentation on Analytics and SAML, we have copied the corresponding configurations of FNMS SAML into the web.config of Analytics. When the Analytics Server is called, communication with the IDP also begins and an initial request for access data (PKI) is made. We have recorded the communication with a SAML tracer and found an error here, including a error message from the IDP (IBM F5) open https://analytics.server/ibmcognos/bi request for access data (PKI) done Browser Error IBM F5 - FBTSML218E The specification for the SAML2.AssertionConsumerService endpoint are not valid Chrome SAML2 Trace <saml2p:AuthnRequest
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="id9a3d3ee252d74447b32d7562e73fe***"
Version="2.0"
IssueInstant="2021-09-05T21:11:44Z"
Destination="https://idp-url/isam/sps/idpextqs/saml20/login"
AssertionConsumerServiceURL="https://analytics-url/ibmcognos/sso/AuthServices/Acs">
<saml2:Issuer>https://fnms-url/Suite</saml2:Issuer>
</saml2p:AuthnRequest> If I have seen it correctly in IIS, Cognos itself does not provide an Authentication ACS endpoint to match information regarding the login, for that the FNMS ACS should be used. Attached is the <kentor.authServices> snippet from Cognos web.config <kentor.authServices
entityId="https://fnms-url/Suite"
returnUrl="https://fnms-url/Suite/AuthServices"
authenticateRequestSigningBehavior="Never"
minIncomingSigningAlgorithm="sha1">
<identityProviders>
<add entityId="https://idp-url/isam/sps/idpextqs/saml20"
signOnUrl="https://idp-url/isam/sps/idpextqs/saml20/login"
allowUnsolicitedAuthnResponse="true"
binding="HttpPost"
loadMetadata="true"
metadataLocation="C:\Program Files\ibm\cognos\idpextqs_metadata.xml">
</add>
</identityProviders>
<serviceCertificates>
</serviceCertificates>
</kentor.authServices> Do any of you have a hint on how to get Cognos to use the correct Autnetication ACS endpoint. I'm also looking for a way to activate debuggin for Cognos SAML as it is possible for the FNMS weui.log (Maybe @kent-au or @fnishikado @fnishikado1 ) FNMS in combination with SAML2 and the IDP Works without problems. Thanks and Best, Dennis
... View more
Sep 02, 2021
02:02 AM
2 Kudos
Hi @Favari0105 , take a look at this post, which covers the same topic. https://community.flexera.com/t5/FlexNet-Manager-Forum/Batch-license-allocation/m-p/106352#M1504 Best, Dennis
... View more
Sep 01, 2021
02:29 AM
Hi @sushant_narula The appropriate settings and permissions are all in place. It really only fails at the connection to the FNMS database as in the screenshot of @carlos_quiros and is due to a problem with TLS1.2, which can be solved by an adjustment via the "Settings Tab" in Cognos. Although the problems and approaches may be different, the community would greatly appreciate your solution so that others with the problem can get to a solution faster. Thanks and regards, Dennis
... View more
Aug 31, 2021
05:13 AM
Hy @carlos_quiros @WheresThePizza could you please share the solution how to get the "settings tab" back to cognos. I'm running into the same problem and as already discussed and would like to change the dispatcher settings to connect to the ContentStore DB. Thanks and Best, Dennis
... View more
Latest posts by dennis_reinhardt
Subject | Views | Posted |
---|---|---|
834 | Feb 15, 2022 03:58 PM | |
1795 | Dec 14, 2021 03:20 PM | |
542 | Dec 14, 2021 02:30 AM | |
40185 | Dec 13, 2021 01:56 PM | |
5427 | Dec 13, 2021 01:53 PM | |
1278 | Dec 13, 2021 01:49 PM | |
1188 | Dec 13, 2021 07:09 AM | |
323 | Oct 12, 2021 07:26 AM | |
1060 | Sep 16, 2021 06:40 AM | |
596 | Sep 16, 2021 03:52 AM |
Activity Feed
- Kudoed FNMS Agent Upgrade with custom wmitrack.ini for mfranz. Apr 28, 2022 02:27 PM
- Got a Kudo for Re: File Scan for Non Windows Server. Feb 15, 2022 04:10 PM
- Posted Re: File Scan for Non Windows Server on FlexNet Manager Forum. Feb 15, 2022 03:58 PM
- Got a Kudo for Re: changes through BA like CC, Location and Role are not reflecting immediately. Feb 09, 2022 11:52 PM
- Got a Kudo for Re: changes through BA like CC, Location and Role are not reflecting immediately. Dec 27, 2021 07:22 AM
- Got a Kudo for Re: Disable docker service or remove from installation. Dec 21, 2021 04:53 AM
- Got a Kudo for Re: Log4j vulnerability - info on how to scan and question about how to determine version on results. Dec 15, 2021 01:47 AM
- Got a Kudo for Re: Disable docker service or remove from installation. Dec 15, 2021 01:14 AM
- Got a Kudo for Re: Disable docker service or remove from installation. Dec 15, 2021 01:09 AM
- Posted Re: Disable docker service or remove from installation on FlexNet Manager Forum. Dec 14, 2021 03:20 PM
- Kudoed Re: Disable docker service or remove from installation for joshstechnij. Dec 14, 2021 03:17 PM
- Got a Kudo for Re: Log4J Detection by FlexNet Inventory Agent. Dec 14, 2021 05:49 AM
- Got a Kudo for Re: changes through BA like CC, Location and Role are not reflecting immediately. Dec 14, 2021 02:49 AM
- Posted Re: changes through BA like CC, Location and Role are not reflecting immediately on FlexNet Manager Forum. Dec 14, 2021 02:30 AM
- Got a Kudo for Re: Security Advisory: Log4j Java Vulnerability (CVE-2021-44228). Dec 14, 2021 02:26 AM
- Got a Kudo for Re: Security Advisory: Log4j Java Vulnerability (CVE-2021-44228). Dec 14, 2021 01:33 AM
- Got a Kudo for Re: Security Advisory: Log4j Java Vulnerability (CVE-2021-44228). Dec 13, 2021 01:58 PM
- Posted Re: Security Advisory: Log4j Java Vulnerability (CVE-2021-44228) on Community Notices. Dec 13, 2021 01:56 PM
- Got a Kudo for Re: Security Advisory: Log4j Java Vulnerability (CVE-2021-44228). Dec 13, 2021 01:56 PM
- Posted Re: Log4j vulnerability - info on how to scan and question about how to determine version on results on FlexNet Manager Forum. Dec 13, 2021 01:53 PM