顯示具有 Quest 標籤的文章。 顯示所有文章
顯示具有 Quest 標籤的文章。 顯示所有文章

2018年12月27日 星期四

升級 Foglight for Virtualization Enterprise Edition to 8.8.5

Understanding product versions

The Management Server and the Agent Manager have been updated to version 5.9.4 for this release.

Supported upgrade path

  • Foglight for Virtualization, Enterprise Edition 8.8.5 may be directly upgraded from version 8.8. 
  • To upgrade from version 8.7.5, 8.7, 8.6, you must first upgrade the virtual appliance to version 8.8, then to version 8.8.5. 
  • To upgrade from version 8.5.5, 8.5, 8.4, 8.3, or 8.2, you must first upgrade the virtual appliance to version 8.6, then to version 8.8, then to version 8.8.5.

Foglight for Virtualization, Enterprise Edition versions

Foglight for Virtualization, Enterprise Edition consists of these key software components:
• Management Server
• Agent Manager
• Cartridges

Component versions

  • Management Server, version 5.9.4
  • NOTE: Foglight for Infrastructure 5.9.4 is embedded with the Management Server.
  • Agent Manager, version 5.9.4
  • Foglight for Action Packs, version 5.6.3.8
  • Foglight Automation, version 5.6.3.8
  • Foglight Capacity Director, version 5.7.7
  • Foglight Capacity Management, version 5.7.7
  • Foglight Capacity Manager, version 5.7.7
  • Foglight Change Analyzer, version 5.7.7
  • Foglight Chargeback, version 5.7.7
  • Foglight for Hyper-V, version 5.7.7
  • Foglight Resource Optimizer, version 5.7.7
  • Foglight for Storage Management cartridge, version 4.6.5
  • Foglight for VMware, version 5.7.7
  • Foglight Net Monitor, version 5.9.4


Preparing to upgrade Foglight for Virtualization, Enterprise Edition

  1. Create a support bundle from your Management Server.
  2. Back up the file system in which Foglight for Virtualization, Enterprise Edition is installed.
  3. Back up your database
  4. Deactivate all agents through the Agent Status dashboard (Dashboards > Administration > Agents >
  5. Agent Status).
  6. If you are currently running the VMware Performance Agent on a 64-bit Management Server, you can use the embedded Agent Manager for the VMware Agent to monitor up to 500 total VMs.

Note for installations monitoring large VMware environments

Some installations monitoring large VMware® environments have customized the VMware agent memory settings. These settings must be reapplied because the upgrade procedure overwrites them with the default settings. 
For each Agent Host with existing VMware Performance agents:
  1. On the agent machine, open the baseline.jvmargs.config file for editing. The file is located in the<Agent_Manager_home>/state/default/config directory.
  2. Make note of the vmparameter.x values. If the values on your agent are different, they must be reapplied after the upgrade.
  3. After upgrading and reapplying the values in the baseline.jvmargs.config file, remove the deployed negotiation configuration settings directory  (<Agent_Manager_home>/state/default/config/deployments), and restart the Agent Manager. The new settings take effect after the Agent Manager is restarted.

Upgrading Foglight for Virtualization, Enterprise Edition from a previous version

The Foglight for Virtualization, Enterprise Edition components (Management Server, Embedded Agent Manager, Cartridges) are all upgraded automatically by the Foglight for Virtualization, Enterprise Edition installer.

  1. Download the Foglight for Virtualization, Enterprise Edition installation package for your platform from the Support Portal.
  2. Manually shut down your Foglight Management Server. Do not depend on the installer to shut down your running Management Server and/or embedded database, due to the timing problem. Ensure that the Management Server has stopped running before launching the Foglight for Virtualization, Enterprise Edition installer. To verify that all Management Server processes have stopped, type the following command: tasklist /v | find "fms"
  3. For extra reliability, you must back up the Foglight database.
  4. Upgrade the existing Foglight for Virtualization, Enterprise Edition installation using the appropriate installer.
  5. The installer detects the earlier version of Foglight for Virtualization, Enterprise Edition. Follow the on-screen upgrade instructions. Select Upgrade and click Next.
  6. After the Foglight for Virtualization, Enterprise Edition application is upgraded, the licensed cartridges are upgraded automatically.






Upgrading the Agent Manager

The embedded Agent Manager is updated as part of the upgrade process. Any additional, external Agent Managers may need to be updated. If the Version of any agent host listed is not 5.9.4, continue following this procedure to upgrade the Agent Manager.
  • To upgrade, select the agent host from the list and click Upgrade. The process may take a few minutes andthe agent host may disappear from the list temporarily while it is restarting.

Upgrading Foglight for Virtualization, Enterprise Edition agents

After upgrading Foglight for Virtualization, Enterprise Edition, the database, and cartridges, the agents used by some of the cartridges must be updated to ensure proper data collection. Specifically, this section describes the procedures for upgrading monitoring agents.

Upgrading the VMware Performance agent

  • Log in to Foglight for Virtualization, Enterprise Edition using an account with administration-level permissions.
  • Deactivate all VMware Performance agents.
    • On the navigation panel, under Dashboards, click Administration > Agents > Agent Status.
    • On the Agent Status dashboard, select the existing VMware Performance agents and click Deactivate.
  • Upgrade the agent package. On the VMware Environment dashboard > Administration tab, select all agent instances from the Agents table, and click Update Agent on the menu bar.
  • Activate all VMware Performance agents. On the VMware Environment dashboard > Administration tab, select the deactivated VMware Performance agents, and click Activate on the menu bar.


Upgrade Foglight for Infrastructure

As part of the transition to Quest Software, Foglight for Infrastructure 5.8.5.8 and higher deprecate the following agent types:
  • DellUnixAgent: Replaced with the new UnixAgentPlus agent type.
  • DellFileLogMonitorAgent: Replaced with the new FileLogMonitorAgent agent type.
  • DellWindowsEventLogMonitorAgent: Replaced with the new WindowsEventLogMonitorAgent agent type.
Install version 5.9.4 of the cartridge as you would a new Foglight for Infrastructure cartridge. Do not delete the older version of the .car file. Install version 5.9.4 over the older version.




















2018年10月15日 星期一

[Active Roles] How to, One Identity Active Roles - 如何彈性的調整 change workflow?



隨著企業的快速發展,AD管理員面臨一個問題: 他們需不眠不休的奮力支援業務需求及滿足稽核人員。每天面對成千上百的新增刪需求,加上授權控制權給不同的管理群組,異動前需要關鍵人員在流程中進行審核等等。

現在透過 One Identity Active Roles (ARS),即可輕鬆有效的保護 AD 和 AAD,解決安全議題並符合法規需求,以ARS自動化工具,便彌補AD和AAD原生工具的不足。

基於定義的管理策略和相關權限,ARS提供全面的特權帳戶管理,使您能夠使用最小權限來委派控制權,也可以OU為單位,賦予使用者或群組的管理權限有效提升IT人員的工作效率。

今天的透過委派管理權限的範例,來說明如何進行彈性的調整。

將PSD這個OU的帳號與群組管理權限,委由特定帳號sguser3,透過瀏覽器即可管理OU。

ARS內建workflow,當委派使用者或群組異動權限給特定帳號時,我們同時可以限定該異動必須先通過審核程序(主管,人資或是IT),始能生效。同時也保留彈性。

建立資料異動的 change workflow

透過瀏覽器,sguser3修改了testuser1的電話號碼,但是必須先經過審核後才會異動。

依公司規範,定義必須的審核層級。


更進一步,我們可以設定白名單與黑名單。
1. 正向表列 – 限定當特定帳號或群組進行異動時,才需要審核流程。(使用 Initiator Condition)
正向表列
2. 負向表列 – 可以將特定名稱的帳戶跳過審核流程。(使用Filtering Condition)

排除清單
將sguser3設定為排除名單

將sguser3設定為排除名單



透過第二種負向表列的方式,我們將PSD OU的委派管理員sguser3,在workflow中設定為排除名單之後,再試著修改testuser1 的電話號碼,就不需要跑簽核流程了。

修改電話號碼

無須審核即可異動。