Viewing the compliance status
A Compliance Status action displays the compliance information for a network span and its associated rule sets.
No actual compliance check is performed during this action run. Instead, the compliance data displayed is retrieved from the database where it had been archived previously during Snapshot and Refresh Status actions.
This action is aimed at persisting the compliance information where it can be readily viewed in the Job Details report (unlike the Compliance Summary report where the results are not persisted for later viewing).
The compliance check is not performed during the Compliance Status action but rather during the Refresh Status action, the results viewed here are only as up-to-date as the most recent Refresh Status or Snapshot.
To view the most up-to-date Compliance information, the user should run the Compliance Summary report and force a re-evaluation.
To view the compliance status
- On the Add Job page, select Add Action > Span Actions > Compliance Status.
Enter information in the following fields:
(Optional) Enter an annotation to help describe the purpose of running the action.
Select a realm, group, multiple devices, or a single device for the Compliance Status action. When the Network Span is Realm or Group, you can use Filter Devices to select which devices to include in the action.
Select this option to view compliance results for all compliance rules applicable to the selected network span, or select a specific set of rule sets.
- To select one or more specific rule sets, click the Add button in the Compliance Status dialog box.
- In the Select Rule Set window, select specific rule sets.
You can do inline filtering to search for rule sets matching a name.
- After selecting specific rule sets click OK to take control back to the Compliance Status action editor with the selected rule sets populated.
- Click OK to add the action to the Job.
After a Job run, the Job details page displays the input parameters and the completion status (for example, Succeeded).
Click on the status value in the Job details page to view the results in a popup. The popup shows the name of the device, the full rule name, configuration trail name, severity, category of the rule and a result indicating whether the compliance check passed or failed.