I’ve started using the REST API in IEM to push baseline by creating the xml and then using the POST method via …/api/actions. The challenge is that you I have to include all the execution settings in the xml, and it becomes difficult managing that with different baselines with different constraints.
Is there a way to push a fixlet (i.e. a baseline) and it would use the fixlet’s default settings (start time, stop time, constraints, etc) rather than having to create the custom xml each time?
right, so you still have to create the xml file for the action. I was under the impression that there was a different way to execute a fixlet, where you don’t have to create the xml and use /api/actions, but instead, you could execute the fixlet via some other method, that uses the default settings of the fixlet.
Yes, you can do exactly what you just mentioned. You still have to create the action XML, but it is very small, it basically just contains a pointer to the source fixlet.
i tried creating a action in this way, with the action xml below and issuing it against the …/api/actions API. The action executes, but doesn’t include the default fixlet settings (i.e. constraints). Did I do something wrong?
That seems correct. So it didn’t have the default constraints of the fixlet itself? I wonder if that means you have to specify them, if possible. I’m not certain why that would be.
In general, you shouldn’t have to generate much xml. You should be able to build a template of the most common cases you need by doing it in the console by hand, and then export the resulting action, and the use that xml as your template.
correct, I sent a default constraint in the fixlet, then executed the fixlet with the above xml action. The constraint did not carry over then into the newly created action in the console.
It’s strange because other fixlet defaults like Start Time (empty), stop time (+ 2days) are included in the console action when they are not specified in the action xml file.
correct… and inside the Settings tag you can submit a blank test task with the proper execution parameters you ll want (like start on, end on, reapply, wait, etc) and export this action to get the proper syntax to update your XML code.
for example, one of my baselines has a default constraint of “run only when in Patching Windows” = “true”. I wish I could execute the baseline via the API and not have to re-create that constraint within the Settings section of the action xml file.
I also have a bunch of constrains in my baseline execution to be satisfied.
I added all the conditions to a automatic group and in the action XML I am just referring to apply if computers belongs to that automatic group under the CustomRelevance tag.