Feb 03, 2021
02:43 PM
That makes sense for most scenarios, but unfortunately for this scenario, and others seen in the past, it doesn't fit with the behavior seen. This typically happens with RHEL 5/6 servers, with identical packages installed, and the setup of the VM the same except for hostname. That's the aspect that is extra puzzling. They have performance, networking and packaging information that populates correctly on servers that do show up in the IaaS report and the ones that do not. Their licensing history matches too. I'm still digging into the minutia to see if there are differences in setup that I am missing. Your explanation makes sense for those devices types you mention. I would expect those results. Unfortunately, these are servers that really should be in the IaaS report. I can PM or e-mail the assessment involved if you can look into what we are seeing. I have a list of approximately 200 servers that are in the asset list but that are missing from the IaaS report.
... View more
Jan 27, 2021
01:07 PM
A recurring quirk that confuses customers, and myself, is the fact that asset counts do not match between various reports. As an example, if you take an asset export and compare it to an IaaS report, there could be a difference of 200+ entries. This assumes that the asset count matches the licensed asset count, 1 to 1. As long as performance metrics have been collected, you would expect the asset count to match the amount of entries in the IaaS report, excluding network devices and NFS devices. Questions: #1: What could cause discrepancies as large as this to occur? #2: What determines an asset being shown in the IaaS report output? Currently licensed only? An asset that has performance data in general regardless of license? Not trying to game the system, but many scenarios exist where assets that were originally licensed were determined to be out of scope and unlicensed accordingly to prevent recurring charges. I've focused on two reports, but there are other reports that will display more or less asset counts compared to the asset export. I'm concentrating on these two for the moment. Thanks!
... View more
Jan 11, 2021
09:40 AM
There are a group of large SAP HANA RHEL systems that are triggering a 'hard failure' on assessment when I suspect that marking this particular error as a soft failure instead of a hard failure, would allow them to complete the assessment. Unfortunately, it is a combination of a kernel limitation in the older versions of RHEL combined with using NetApp snapshots. Without marking this as a soft failure, they get marked as 'Virtual-unknown' instead of 'Virtual-Generic Server' Is there a way for CS to detect this and continue on, or is the behavior not going to change? "Failed the command 'df -P': df: ‘/opt/customer/openhubintl/.snapshot/hourly.2020-10-04_2305’: Stale file handle df: ‘/opt/customer/openhubintl/.snapshot/hourly.2020-08-31_2105â" The related RedHat article about it - workarounds aren't working. https://access.redhat.com/solutions/3609771
... View more
Nov 05, 2020
03:32 PM
2 Kudos
High priority / customer blockers / time killers Unhidable ‘Unknown’ in Reports scare sales execs and C-Level executives - There should be a toggle to display or not display ‘Unknown’ in any graphic report, or globally. It is difficult to avoid having to say ‘I don’t know’ when asked what is in there and why it is labeled unknown. This would avoid that conversation. I’ve made custom pie charts based off the numbers to avoid showing unknown manually. There are even different ‘unknown’ values shown, depending on what page in the portal you are on. Windows Domain Admin requirement sets off alarms with most security teams - Local admin should be a supported scenario, or include instructions on how to configure the WMI repositories so that the information can be obtained with a user that can only do WMI calls and have standard user rights to run the netstat command. Exports limited to 10k items on Asset page and other pages - The end user ends up trying to figure out how to filter down to an acceptable size and then combine the files afterwards. Ability to exclude scanning of a list IPs inside the scanned IP range - Example: Scanning certain servers could cause a production outage or server crash Medium priority / discovery optimizations Ability to enable/disable credential use per subnet - This would reduce discovery scans from 24 hours at some customers potentially in half due to the time it takes for multiple Windows credentials to fail. Many times, certain credentials will be only required for certain subnets. If I could disable the attempted use of ‘CompanyXYZ’ Windows credentials on “CompanyABC” subnets, or disable use of certain modules (WMI, SSH, Database, SNMP) on specific subnets. *Thousands* of Asset Error entries would be eliminated, and it would be easier to digest. This would reduce false alarms on intrusion detection systems, too. Real world example: ~10 Windows credentials are attempted on every Windows server because there are 10 credentials entered into the appliance. Scoping these to specific subnets would save discovery time and error messages. “Limited rights” discovery option – gather as much information as possible without sudo access or Windows Domain Admin. A standard user in the SSH module can gather quite a bit of information by default. May convince a customer that was not onboard, to get onboard additional access, after they see how it operates. If you have ‘Opt-out’ SNMP scans, do not even attempt them - Less errors logged, and less unnecessary probing, potentially over slow links. Documentation layout on portal is confusing for most customers and implementers - Hard to export information to send to the customer to prep their environment for the product. Need to scrape the webpage and put into a Word or PDF file manually. Allow the HTML pages related to it be downloaded and rendered locally on their system or export to PDF. Export to Excel is only available in limited spots - In the Reports section, you can export directly to an Excel file. It seems like the same technology could be used to export to Excel instead of CSV on any page. CSVs. The reports page operates completely different than the rest of the portal. Phase of Discovery does not provide adequate feedback - Show a percentage of the current subnet being scanned on the VM and expose the information that is available from the VM console on the portal. Display how long it has been running and when it started. an average duration per subnet or how long the average scan has been taking. Ability to disable “RN150 offline” notifications Ability to opt-out per user of e-mail updates about the appliance - on discovery scans or updated assets or other notifications. Adding credentials and subnets requires access to RN150 - Usually have to VPN into RDP into the RN150 access inside the environment. This may be on purpose, but subnets are already exposed on the portal. Adding/deleting subnets from the portal would be ideal. Timesaver and reduction in user account creation requests for internal access into the customer’s environment. Allow labels for the subnets be added to the CSV imported into the RN150 - The usage of “Update Locations” page use would drop quite a bit. Time saved and less prone to error. Timesaver. Low/nice to have/nit-picking Use PowerShell remoting instead of WMI – ServiceNow Discovery has a PowerShell option that is very handy when WMI calls are failing on certain servers. Never modify the hostname – Sometimes “Orphaned –“ and “RISCdecom” are appended to the hostname in exports. Ideally, these would be their own field and not something that mangles the hostname. Licensing page should have the same filters as the Assets page - Some Asset strings would be useful to filter for licensing purposes. Allow licensing to be included as a field in the Stack management or Tag management, or create a dedicated import page - It is much easier to license in bulk if it could be done in Excel. Expose or track when a server was licensed as a field or premade tag - This would help billing and management and should be an easy win. Save the state of expanded and hidden graphs on the portal pages – on the backend or as a cookie. I go to the asset page every day and I am always hiding graphs every time. It would reduce the backend server load too because the statistics wouldn’t have to be queried if the graph is going to be hidden. It can take a long time to render when people just need access to the Asset listing – “Your assets at a glance” and “Statistics” are an instant hide every time. This is almost implemented already with the ‘Save or Load View” functionality – allow a default to be saved. If this is available already, it isn’t obvious how to do. No ability to remove subnets/assets once entered Enable SSH Compression for less bandwidth usage – if using openssh, it is “-C” on the command line. May already be enabled. May be overkill “RISCdecom –“ and “RISCdecom-“, without the space, used in certain exported fields – Search/Replace easier if it is consistent in use inside exports. Very nit-picky. Allow 'Validate' to test SSH module auth during setup before a successful SSH test has occurred Ability to lookup 3 letter 'authentication' text to see which set of credentials they were, in the portal. Helpful for debugging the Asset Errors.
... View more
Nov 05, 2020
02:41 PM
1 Kudo
Curious what this part of the database report actually means? What is the metric being analyzed? There are approximately 300 database user credentials entered into the appliance. Does "No" (cyan) mean that it was allowed a connection into DB without authentication? Or: Does "No" mean that the credentials supplied did not work? Also, the [Export] option is unavailable for the same graph.
... View more
About
USA
Latest posts by atiensivu
Subject | Views | Posted |
---|---|---|
522 | Feb 03, 2021 02:43 PM | |
569 | Jan 27, 2021 01:07 PM | |
680 | Jan 11, 2021 09:40 AM | |
1521 | Nov 05, 2020 03:32 PM | |
474 | Nov 05, 2020 02:41 PM |
Activity Feed
- Got a Kudo for Re: Have an idea for changing Foundation/CloudScape? The product team wants to hear it. Apr 19, 2021 11:26 AM
- Posted Re: Asset count discrepancies between various reports on Foundation/CloudScape Forum. Feb 03, 2021 02:43 PM
- Posted Asset count discrepancies between various reports on Foundation/CloudScape Forum. Jan 27, 2021 01:07 PM
- Posted Repost from e-mail - NetApp stale NFS 'df' failures on Foundation/CloudScape Forum. Jan 11, 2021 09:40 AM
- Got a Kudo for Re: Have an idea for changing Foundation/CloudScape? The product team wants to hear it. Nov 09, 2020 01:47 PM
- Got a Kudo for Clarification of "DBs with Credentials" on Database Report. Nov 09, 2020 12:19 PM
- Posted Re: Have an idea for changing Foundation/CloudScape? The product team wants to hear it on Foundation/CloudScape Forum. Nov 05, 2020 03:32 PM
- Posted Clarification of "DBs with Credentials" on Database Report on Foundation/CloudScape Forum. Nov 05, 2020 02:41 PM
- Tagged Clarification of "DBs with Credentials" on Database Report on Foundation/CloudScape Forum. Nov 05, 2020 02:41 PM
- Tagged Clarification of "DBs with Credentials" on Database Report on Foundation/CloudScape Forum. Nov 05, 2020 02:41 PM
- Tagged Clarification of "DBs with Credentials" on Database Report on Foundation/CloudScape Forum. Nov 05, 2020 02:41 PM