Issue with Bigfix Compliance Report

Hi All,

I’m facing an issue while trying to fetch the compliance report for the custom AIX checks we created.

Initially, we developed these checks (using the SCM Custom Relevance Content Wizard) in our infrastructure and later imported them into the customer’s environment. At that time, the reports were generated successfully, and everything was functioning as expected.

However, last week we encountered an issue related to the desired value, its title, and the one-to-many mapping between fixlets and analyses. (We had copied the out-of-box checks and edited them, which made them different from the original custom checks.)

To resolve this, we decided to recreate all of these checks in our infrastructure (again using the SCM Custom Relevance Content Wizard) and re-import them into the customer environment, following the same process as before. We also removed the old fixlets and analyses and imported the new ones, keeping the linkage intact.

Now, the issue we’re facing is that, on the Compliance Dashboard, the site appears greyed out, and all checks are showing as non-applicable.

I’ve attached a screenshot below for reference:

image

I have tried creating new site (this one and all the sites mentioned above has been created via SCM custom checklist wizard) and importing the checks here and I’m facing the same issue.

any kind of help is appreciated. Thanks in advance.

Might it be possible that you do now have no applicability fixlet in your new site?

I think it might be possible that I have imported the applicability fixlet from my infra (let’s call it A) to the customer’s infra(let’s call it B) along with the fixlets. I will check it and let you know. but can applicability fixlet of different infrastructure cause this kind of issue? because I’m most certain that the applicability fixlet isn’t missing.

The Applicability Fixlet should be generated by the same SCM wizard.

There are metadata in the Applicability and Check fixlets that are generated with the wizard, and if they don't match then the checklists aren't going to perform as expected.

I don't know that we have any guidance for copying checks between Bigfix deployments. I'm not sure whether that works at all, but for it to have any chance of working at all, I'm pretty sure you'd have to copy both the check fixlets and the applicability fixlets so that they stay in sync with each other.

Hello @JasonWalker @MatthiasW ,

Found the issue.

The mismatch in the applicability Fixlet was causing the problem. To Troubleshoot, I created the custom site using the SCM Wizard in the customer’s environment and then imported the checks and analyses (barring the applicability fixlet, of course) from our infrastructure into theirs.
In this setup, the applicability Fixlet belonged to their environment, while the checks were from ours — and it worked! The reports are now displaying correctly for this site.

And to answer your question, Jason, yes, we can copy checks from one BigFix deployment to another, as long as we import them in pairs (Fixlets and Analyses) and keep the linkage intact.

Thanks a lot for your help!!

3 Likes