generally MS15-078 to MS15-090 patches are relevant to my endpoints but while i create those fixlets into baseline it will not come applicable to even single endpoint. Kindly share your views to short out this issue ASAP.
Note:
BES Client service running perfectly
2.Telnet to main server from client is successful
ping and all connectivity is good
from native (MS15-078) fixlet can deploy independently to endpoints but baseline not get any applicable machines for same fixlet.
You need to validate communications in the other direction as well.
Server to Endpoint.
The default method is a UDP/52311 message sent to âregisteredâ endpoints (Relays or Endpoints) when new content is available for evaluation.
If UDP isnât an option, verify that you have Command Polling enabled. Without UDP or Command Polling, endpoints will only gather new content once every 24 hours by default.
when you create a baseline, you can locate it in one of these sites (master action site, operator site or any other custom site)
you can not create it in âpatches for Windows siteâ (but domain may be âpatch manageentâ)
if you dont create the baseline in the master action site, you should copy the components of baseline into the site of baseline.
@vikki
I donât understand where you are having trouble. You should not have to copy any content anywhere to make a baseline work. As you add content to the Baseline, the Relevance and Action components for each component is added directly to the Baseline file itself.
The way I manage my Monthly Microsoft baselines is as follows âŚ
Imagine I have a Custom Site named âCustom Contentâ
All Windows Systems are also subscribed to the Patches for Windows site.
In my case, All Computers are subscribed to the âCustom Contentâ site.
Once the Monthly Microsoft patches arrive from IBM and are gathered by BigFix, I create my baselines.
Example: 2015-08 : Microsoft Critical/Important Patches
The Relevance in the Baseline is adjusted to âWindows of Operating Systemâ since the site has Macintosh and Linux hosts as well as Windows systems and I donât want them to bother evaluating the Windows only content.
I add all the Critical and Important patches released that month to the Baseline.
I then save the Baseline in the âCustom Contentâ site.
Within a few minutes Iâll start to see computers reporting relevant to the baseline.
Note:Do not add âhundredsâ of fixlets/tasks to a single baseline or it could take a VERY long time for each computer to evaluate the baseline and report if it is relevant to it. This is why I create two baselines each month. One for Critical/Important Patches and another for the rest. Until you can determine what is going on, I recommend adding only one or two fixlets to the Baseline to keep evaluation times as low as possible.
Do you have both Fixlets and Tasks in the baseline? Iâve been having the same problem as you, and that seems to be the problem. If I create a baseline with only fixlets or only tasks, then every computer that is relevant for ANY of the components will show the baseline as relevant. If I mix fixlets and tasks in the same baseline, it looks like a computer has to be relevant for ALL components before any of the components will be considered relevant. I have no idea if this is expected behavior or a bug, but itâs annoying and not well documented anywhere that I was able to find.
If this is behavior youâre seeing you should file a PMR.
If a fixlet is in a baseline and a computer is relevant for the fixlet, the computer is relevant for the baseline.
Tasks only factor into Baseline relevance if, âBaseline will be relevant on applicable computers where this component is relevantâ is checked on the component. If this is checked then a computer that is relevant for the task, is relevant for the baseline. If it is not checked then only the relevance of other components in the baseline are considered.
Mixing Tasks and Fixlets should have no effect on how baseline relevance is calculated
Where is the option to check âBaseline will be relevant on applicable computers where this component is relevant?â I donât see that option anywhere.
That seems to be the underlying issue. For whatever reason, the fixlets are coming in with that setting checked by default. For what Iâm doing, the fixlets arenât necessarily relevant for all of the computers, but the tasks are. To get the effect Iâm expecting, I needed to go to each component and make sure that option isnât checked.
Thank you. This has been a real annoyance for us for a while.
I think you might have that backward â you want this checked.
If you want the fixlet or task to âcountâ then you need this checked.
Essentially for a computer to run a baseline it needs to be relevant for one of the tasks or fixlets in that baseline that has this box checked. Generally you want this checked on every item in the baseline.
Itâs checked by default for fixlets itâs not checked by default for tasks.
I have to run but Iâll edit this to explain why a little later.
You donât want the box checked if the task or fixlet does not have relevance that goes to false, otherwise the baseline will reapply infinitely if it is set to reapply⌠but otherwise yes, if the item has relevance that goes to false after completing, then the box should be checked.