Viewing Change-Tracking Results  for FIM compliance in the Console


This procedure describes how to view the results of a PCI-FIM Batch Job.

This procedure assumes that you ran the Snapshot Job (or the Batch Job containing it) at least two times and that a change was made to a tracked object in between the job runs. Otherwise, no changed objects are available to view.

  1. In the Jobs folder, right-click the Snapshot Job and click Show Results.
     Alternatively, navigate to the Snapshot Job from the Batch Job as follows:
  2. Right-click the Batch Job and select Show Dependency.
    worddave404b7d25c63a5d7f82bc88ff5f34935.png
  3. In the content editor, click the Downward tab.
    worddavc98a5a42fecb8a3d3d8ec1c23e89a7d2.png
    The Batch Job expands to show the Discover and Snapshot Jobs contained in the Batch Job.
    worddav03a60c525950f1d2e39e0735ed9b8535.png
  4. Right-click the Snapshot job and select Go to Job.
  5. Right-click the job run and select Show Results.
  6. In the content editor, notice the Error and Warning icons next to the Snapshot Job run. Right-click and select Show Log to investigate.
  7. Click the most recent Snapshot Job run to expand it. Then click Server View. Then click a server of interest.
    worddavd2a629062b2dcb4bd0ba806059e90da2.png
  8. In the content editor, for each server, click the Change Tracking tab.
    worddave96daa5fcef677c305e8885e1e4dc015.png
  9. In the Change Tracking tab, notice the following:
    • Scan the Total Changes column. The expected result in this column is all zeros. You should investigate the reasons behind any other value.
    • Red x on files and folders means that the object was not found.
    • Red x on a snapshot means that an error occurred while gathering the snapshot data.
  10. To investigate a changed folder, click the Snapshot tab.
    worddav00d11d19070dcf8974d392e4d8ebc6e8.png
  11. In the Snapshot view, click the folder that you want to investigate.
    worddavd71ee74049a94166bf4d312261585fc5.png
    The expanded view shows the unexpected, added files.
    worddav1f18b0d0149f33600053991a6a7f1a7b.png

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*