Documentation update To provide a better user experience, we have now created a separate documentation space for BMC Helix Automation Console (previously called BMC Helix Vulnerability Management). Users of BMC Helix Automation Console can find the latest documentation at BMC Helix Automation Console..

Configuring the BMC Discovery connector


BMC Discovery connector establishes connection with BMC Discovery (on-premises only) to find all the assets in a network. BMC discovery obtains information about the assets even if they are not enrolled in the endpoint manager, TrueSight Server Automation. As an administrator, when you integrate BMC Helix Automation Console or TrueSight Automation Console with BMC Discovery, you can identify which assets in your environment are not included in vulnerability scans. These are blind spots, and they represent potential security risks. The blind spot assets appear on the Discovered Assets page. This helps to ensure that the discovered assets are scanned for missing patches and vulnerabilities.

Important

When you edit the connector configuration, ensure that the server belongs to the Load Balancer setup or the Disaster Recovery setup in the same environment as the existing connector host. If you specify a new server outside of the Load Balancer setup or the Disaster Recovery setup, the existing data is duplicated leading to confusion and mismanagement.

Before you begin

Before running the connector, ensure that the connector is installed and run on Windows or Linux operating systems that match the following criteria:

  • AdoptOpenJDK Runtime Environment 18.9 (build 11.0.7+10) is installed on the connector host
  • Port requirement as below - 

    Port

    Protocol

    From

    To

    Notes

    443

    HTTPS

    Connector

    Discovery Server  and Internet

    Outbound

    open and usable port on connector VM

    HTTPS

    Discovery Server 

    Connector

    Inbound

Configuring the BMC Discovery connector

After installing TrueSight Automation Console, BMC Discovery connector is available for configuration on the Connectors page.

To configure the connector, do these steps: 

  1. Log on to TrueSight Automation Console using the Server Automation profile and user. 
  2. Go to the Briefcase.pngbriefcase menu on the top right, and click Connectors.
  3. On the Manage Connectors page, click theimage2020-7-7_13-33-33.pngoption against BMC Discovery Connector and click Edit.
  4. On the Update a Connector page, provide the following details: 
    1. Enter the endpoint URL, in an FQDN format, with the port number where BMC Discovery is available
    2. Select one of the authentication type: 
      • Token Based: Provide the token.
      • User Credential Based: Enter a username and password required to log on to BMC Discovery. 
        If using a user credential based approach, a service account is created for this integration.
        After entering the password, click Save.
    3. Select one of the Business Service Configuration option: 
      • Create Business Services for all Business Application Instances containing cloud resources
      • Create Business Service based on Subgroup name where manual Group name is: Provide a group name.
    1. In the Collection Mode area, specify the data collection interval. 
      By default, the time interval is 60 minutes. Minimum acceptable is 5 minutes and maximum is 10080 minutes.
  1. Save changes. 
  2. Clickimage2020-7-7_13-33-33.png> Enable to run the connector with the new changes. 

Enabling debug mode

BMC recommends that you do not modify any other configuration files available in the /config directory. However, you can enable the debug mode on the connector to obtain detailed logging information.

Do this:

  1. Press CTRL+C twice to stop the connector, if its already running
  2. Go to <ConnectorLocation>/config, open the collector.properties file, set  the following parameter to debug, save the file

    ######## ADVANCED CONFIGURATION #########
    config.log_level=debug
  3. Restart the connector.

Where to go next?

Now that you have successfully configured the connector and added a service account, based on the data refresh cycle configured in the service account, the assets appear in Automation Console, under Assets > Discovered Assets page. To view discovered assets, see, Working-with-assets.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*