Is there any way to create an exclusion list for each fixlet in bigfix? What we want to be able to do is select a fixlet and then exempt certain servers fron reporting it as applicable or from recieving it. Similarly, we want to be able to select on a server and add fixlet exlusions to it or view the current exclusion list.
Is this a existing capability we have overlooked? If not, how would one do it?
I am also interested in exemption and exclusion capabilities at the specific machine for a specific fixlet. I’m not seeing much in the documentation or here on the forum. Any information would be greatly appreciated.
I’m also interested in a solution for this. We have a few developer machines that don’t always deal well with patching, so they need to be dealt with manually. We want them patched eventually, but not along with everything else in the environment.
One solution might be to lock those computers until you know they’ve been patched appropriately. Bleh.
What if during a patch deployment you applied the fixlet to all computers
except
those in a manual group (“the don’t patch us group”)?
Not sure if there is a better solution, but I’d love to hear it!
‘do not patch’ groups would probably work if I were only concerned about a small number of machines. We are going to use that for some circumstances but it’s not going to cover everything.
Part of my problem is that we’re looking at it from both a ‘do not patch’ perspective but also from a reporting perspective… and we’re talking more than just a handful of machines. Some report users want to see all the machines regardless of exclusions, others want to see only those that truly need the patches. We’re leaning towards creating duplicate fixlets where we can set the relevance to exclude the appropriate machines. But that complicates overhead and reporting both. Which is why I’m looking for alternative ideas.