Changes for page Agentless Scanner
Last modified by Sabrina V. on 2026/08/10 09:15
From version 3.1
edited by Sabrina V.
on 2026/06/01 12:08
on 2026/06/01 12:08
Change comment:
There is no comment for this version
To version 5.1
edited by Sabrina V.
on 2026/08/10 09:15
on 2026/08/10 09:15
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -88,98 +88,105 @@ 88 88 You should only change these settings if requested to do so by Aagon Support. 89 89 {{/aagon.warnungsbox}} 90 90 91 - Abgesehenvondenbeidengenannten Einstellungen,könnenSieimEintragClient Import Destinationfestlegen,wiemitdengefundenenClientsunddenerfasstenDatenumgegangen werdensoll.Sie könnenzwischenfolgendenOptionen wählen:91 +In addition to the two settings mentioned above, you can specify in the “Client Import Destination” entry how the detected clients and the collected data should be handled. You can choose from the following options: 92 92 93 -* //Inventory// – DasInventorywirdmitdenClients inklusiveder erfasstenDatenbefüllt94 -* //AgentDistribution// – Die erfasstenClientswerdeninderAgenteninstallationin ACMP eingetragen95 -* //Inventory and AgentDistribution// – Be ideVorgängewerden ausgeführt93 +* //Inventory// – The Inventory is populated with the clients, including the collected data 94 +* //AgentDistribution// – The detected clients are added to the ACMP Agent Installation 95 +* //Inventory and AgentDistribution// – Both processes are executed 96 96 97 -[[Active Directory Agent konfigurieren>>image:Agentless Scanner_AD Agent.png||alt="Active Directory Agent konfigurieren"]]97 +[[Configure the Active Directory Agent>>image:Agentless Scanner_AD Agent.png||alt="Active Directory Agent konfigurieren"]] 98 98 99 + 99 99 == WMI Scanner == 100 100 101 - DerBereich WMI Scannerkönnen Sie,wieschonzuvor beimAD Agent,dieEinstellungenfür denPfadderMessageQueueunddieAnzahl der internenIPScannerThreads fürdenWMI Scanneranpassen.102 +In the WMI Scanner section, just as with the AD Agent, you can customize the settings for the message queue path and the number of internal IP scanner threads for the WMI Scanner. 102 102 103 103 {{aagon.warnungsbox}} 104 - DieseEinstellungensolltenSienurnachAufforderungdurchdenAagon-Supportändern.105 +You should only change these settings if instructed to do so by Aagon Support. 105 105 {{/aagon.warnungsbox}} 106 106 107 -[[WMI Scanner konfigurieren>>image:Agentless Scanner_WMI Scanner.png||alt="WMI Scanner konfigurieren"]]108 +[[Configure the WMI Scanner>>image:Agentless Scanner_WMI Scanner.png||alt="WMI Scanner konfigurieren"]] 108 108 109 - Abgesehenvondenbeidengenannten Einstellungen,könnenSieim Eintrag//Database Request Frequency//festlegen,inwelchemIntervall(inStunden)die ACMP Datenbank geprüftwerdensoll.BeidieserPrüfungwerdenalleClientsermittelt,welchevom//AD Connector//erfasstwurden,fürdie aber nochkeineDatenvorhandensind.DieseClientswerdenschließlich an denWMI Scannerübergeben und eswirdeinScanderWMI derClientsangestoßen,in dem die erweitertenDatenundEigenschaftenderClientsausgelesenwerden.110 +In addition to the two settings mentioned above, you can use the //Database Request Frequency// entry to specify the interval (in hours) at which the ACMP Database should be checked. During this check, all Clients that have been detected by the //AD Connector// but for which no data is yet available are identified. These clients are then passed to the WMI Scanner, which initiates a scan of the clients’ WMI to retrieve their advanced data and properties. 110 110 111 -Un ter //Domain Credentials//könnenBenutzerkontenhinterlegtwerden,die Administratorrechteauf denzu scannendenClients besitzen.SiemüssenhiermindestenseinenBenutzer eintragen.GehenSiedafürfolgendermaßenvor:112 +Under //Domain Credentials//, you can specify user accounts that have administrator rights on the clients to be scanned. You must enter at least one user here. To do so, follow these steps: 112 112 113 -1. Klicken Sie auf den Plus-Button, um das Dialogfenster für die Credentials zu öffnen. 114 -1. Tragen Sie unter //Domain name (FQDN)// den „Fully Qualified Domain Name“ der Domain ein, deren Clients gescannt werden sollen. 115 -1. Trage Sie bei //User Name// den Benutzernamen ein. Dieser muss nach dem Prinzip Benutzer@FQDN „User Principal Name“ (UPN) aufgebaut sein.{{aagon.infobox}}Der zuerst angegebene Domain name und der FQDN des Benutzers müssen nicht identisch sein. Der Domain name stellt einen Filter der übergebenen Clientdaten dar. So werden nur Clients gescannt, welche nach ACMP Datenbank zur entsprechenden Domain gehören. {{/aagon.infobox}} 116 -1. Tragen Sie bei Password das Passwort für den Benutzer ein. 117 -1. Klicken Sie auf den OK-Button, um Ihre Angaben zu bestätigen und das Dialogfenster zu schließen. 114 +1. Click the plus button to open the credentials dialog box. 115 +1. Under //Domain name (FQDN)//, enter the “Fully Qualified Domain Name” of the domain whose Clients are to be scanned. 116 +1. Under //User Name//, enter the username. This must be formatted as “User@FQDN” (User Principal Name, UPN). 118 118 119 -[[Domain Credentials hinterlegen >>image:Agentless Scanner - Domain Credentials.png||alt="Domain Credentials hinterlegen"]] 118 +1. {{aagon.infobox}}The domain name specified first and the user's FQDN do not have to be identical. The domain name acts as a filter for the client data that is passed. This ensures that only clients that belong to the corresponding domain according to the ACMP Database are scanned.{{/aagon.infobox}} 119 +1. In the “Password” field, enter the user password. 120 +1. Click the OK button to confirm your entries and close the dialog box. 120 120 121 - NunkönnenSiebei Bedarfnoch weitereDomänen mit entsprechendenBenutzerangaben hinzufügen.122 +[[Enter Domain Credentials>>image:Agentless Scanner - Domain Credentials.png||alt="Domain Credentials hinterlegen"]] 122 122 124 +You can now add additional domains with the corresponding user credentials as needed. 125 + 123 123 == XML Importer == 124 124 125 -W ährendClientsmit Windows-Betriebssystemüberdie beschriebenenSchrittemithilfedesAD inventarisiert werdenkönnen,erfolgtdieInventarisierungvonLinux-undMacOS-Clientsdurch denEinsatzvon XML-Dateien.DabeiwerdenfolgendeArbeitsschritte fürdieInventarisierung durchgeführt:128 +While clients running the Windows operating system can be inventoried using the steps described above with the help of AD, Linux and macOS clients are inventoried using XML files. The following steps are performed for the inventory: 126 126 127 -1. AusführungeineslokalenPython-SkriptsaufallenLinux-undMacOS-Clientsmithilfedes Client CommandsLinux-undMacOS-Inventarisierung.128 -1. Automati scheErzeugung von XML-Dateien(eineDatei proClient)auf einerspezifischenNetzwerkfreigabedurchdasSkript,in denenjeweilsallegesammeltenInformationendesClientsgespeichertsind.129 -1. Die erzeugtenXML-DateienwerdendurchdenXML Importerausgelesen, die enthaltenenInformationenwerdenerfasstundschließlichinderACMP Datenbank hinzugefügt.130 +1. Execution of a local Python script on all Linux and macOS clients using the “Linux and macOS Inventory” Client Command. 131 +1. Automatic generation of XML files (one file per client) on a specific network share by the script, each containing all the collected client information. 132 +1. The generated XML files are read by the XML Importer; the information they contain is captured and finally added to the ACMP Database. 130 130 131 - Daim Agentless Scannerselbstnur derXML-Import (Arbeitsschritt3)durchgeführt wird,wird andieserStelleauchnurdieKonfigurationdesXML Importersbeschrieben. FürweiterführendeInformationenzur AusführungdesPython-Skriptsundder ErzeugungderXML-Dateien(Arbeitsschritte 1und 2), lesenSiebittedenAbschnittLinux-undMacOS-Inventarisierung.134 +Since only the XML import (step 3) is performed within the Agentless Scanner itself, only the configuration of the XML Importer is described here. For more information on executing the Python script and generating the XML files (Steps 1 and 2), please refer to the section on Linux and macOS Inventory. 132 132 133 -I mBereich //XML Importer//müssenSiefürdieInventarisierung derLinux- undMacOS-Clientsbei//Reader//dieNetzwerkfreigabenangeben,aufder diezuimportierendenXML-Dateienhinterlegtsind.BeiderVerwendungdesXML ImportersmüssenSie folgende Hinweisebeachten:136 +In the //XML Importer// section, you must specify the network shares under //Reader// where the XML files to be imported are stored for the inventory of Linux and macOS Clients. When using the XML Importer, you must observe the following notes: 134 134 135 -* SolltenzweiClientsihreDateninderselbenXML-Dateispeichern,soüberschreibtderzweiteClient die Daten des ersten.136 -* Nach demImportierenwerdendieXML-Dateiengelöscht.137 -* DefekteDateienoderDateien,dienicht fürdenXML Importerbestimmt sind, werdenebenfallsgelöscht.Daherdürfeninder Freigabe nur Dateien fürdenXML Importerhinterlegtwerden.138 -* Esistnichtmöglichdie XML-DateienineinemUnterverzeichnisderFreigabe abzulegen139 -* DieSoftware-Inventarisierungmit demPaketmanager„dpkg“ kanneinigeZeitin Anspruch nehmen(15-20 min).DieSoftwareinventarisierungkannjedochunter„Options“inder OberflächedesClientCommandsausgeschaltet werden.140 -* Linux SoftwarewirdstandardmäßigimLizenzmanagementausgeblendet,dagrundsätzlichdavon ausgegangen wird,dassessichumOpenSourceSoftwarehandelt.Siekannjedochauch wiedereingeblendetwerden.138 +* If two Clients save their data to the same XML file, the second Client will overwrite the first Client’s data. 139 +* After importing, the XML files are deleted. 140 +* Corrupted files or files not intended for the XML Importer are also deleted. Therefore, only files intended for the XML Importer may be stored on the network share. 141 +* It is not possible to store the XML files in a subdirectory of the network share 142 +* Software inventorying using the “dpkg” package manager may take some time (15–20 min). However, software inventorying can be disabled under “Options” in the ClientCommand interface. 143 +* Linux software is hidden by default in License Management, as it is generally assumed to be open-source software. However, it can be made visible again. 141 141 142 - SiekönnenzwischendreiverschiedenenReader-Typenwählen(FTP-, SCP-und Share Reader).DieKonfigurationderverschiedenenReaderistim Grundsatz gleichaufgebaut:145 +You can choose between three different reader types (FTP, SCP, and Share Reader). The configuration of the various readers follows the same basic structure: 143 143 144 -* Pfad des Verzeichnisses, in dem die XML-Dateien hinterlegt sind {{aagon.infobox}}Beachten Sie, dass der FTP-Reader nicht das FTP-Root unterstützt. Es ist daher notwendig, dass Sie ein Unterverzeichnis angeben. {{/aagon.infobox}} 145 -* Benutzer, der über Zugriffsrechte auf die Verzeichnisse verfügt 146 -* Domain, in der der Benutzer angelegt ist 147 -* Passwort für das Benutzerkonto 148 -* Pfad des Verzeichnisses, in dem alle Dateien vor dem Import lokal als Sicherheitskopie zwischengespeichert werden 149 -* Maximale Anzahl von Inventardateien, die gleichzeitig aus dem Verzeichnis importiert werden 150 -* Zeitangabe in Sekunden, wie oft der Reader nach einem Scan warten soll, bis er das Verzeichnis nach neuen XML-Dateien scannt 147 +* Path to the directory where the XML files are stored 151 151 152 -[[Reader konfigurieren >>image:Agentless Scanner_XML Importer_Share Reader.png||alt="Reader konfigurieren"]] 149 +* {{aagon.infobox}}Please note that the FTP reader does not support the FTP root directory. You must therefore specify a subdirectory.{{/aagon.infobox}} 150 +* User who has permissions for the directories 151 +* Domain in which the user is created 152 +* Password for the user account 153 +* Path to the directory where all files are temporarily stored locally as a backup before import 154 +* Maximum number of inventory files that can be imported from the directory at the same time 155 +* Time in seconds that the Reader should wait after a scan before scanning the directory again for new XML files 153 153 154 - Im Eintrag //Max queue length// können Sie die maximale Anzahl angleichzeitig zuverarbeitendenXML-Dateien begrenzen. Weiterhin können Sie imEintrag//Waiteveryncycles// festlegen, dassder Verarbeitungsvorgang nach einer gewissen AnzahlnanverarbeitetenXML-Dateienunterbrochenwerdensoll. DieDauerderWartezeitkönnen Sie im Eintrag//Wait time// einstellen. Auf dieseWeise ist es möglich die Datenbank zu entlasten.157 +[[Configurate Reader>>image:Agentless Scanner_XML Importer_Share Reader.png||alt="Reader konfigurieren"]] 155 155 159 +In the //Max queue length// entry, you can limit the maximum number of XML files to be processed simultaneously. Additionally, in the //Wait every n cycles// entry, you can specify that the processing should be paused after a certain number (n) of XML files have been processed. You can set the duration of the wait time in the //Wait time// entry. This allows you to reduce the load on the database. 160 + 156 156 == Services == 157 157 158 -I mBereich ServiceskönnenSiedieeinzelnenDienstedesAgentless Scanners starten und stoppen.163 +In the “Services” section, you can start and stop the individual services of the Agentless Scanner. 159 159 160 160 {{aagon.infobox}} 161 - BeachtenSie,dassSievordemStarten oderStoppen einesDienstes alleÄnderungenüberSave speichernmüssen,bevoreinStarten/Stoppenmöglichist.166 +Please note that before starting or stopping a service, you must save all changes by clicking “Save” before you can start or stop the service. 162 162 {{/aagon.infobox}} 163 163 164 -= Zusätzliche Anpassungen in der Konfigurationsdatei des AD Connectors = 165 165 166 -Neben den Angaben, die Sie in der Konfigurationsoberfläche des Configuration Manager machen können, haben Sie die Möglichkeit, weitere Einstellungen in der Konfigurationsdatei des AD Connectors vorzunehmen. 167 167 168 - SpeichernSiedazu zunächstdie im ConfigurationManagergetätigten Eingaben. Öffnen Sie nun die KonfigurationsdateiConfiguration.xml, dieSie im Dateiverzeichnis //Aagon/Configuratio//nfinden.171 += Additional Customizations to the AD Connector Configuration File = 169 169 170 - MithilfederXML-Tags<OuAllowList>,<OuDenyList>und<OuRuleOrder> istes Ihnenmöglich festzulegen,aus welchenOUsComputerobjekteimportiertwerden sollen.DieverschiedenenXML-Tags habenfolgendeFunktionen:173 +In addition to the settings you can customize in the Configuration Manager interface, you can also make continuing customizations in the AD Connector configuration file. 171 171 172 -* <OuAllowList> - Liste mit allen OUs, die ausgelesen werden 173 -* <OuDenyList> - Liste mit allen OUs, die nicht ausgelesen werden 174 -* <OuRuleOrder> - Reihenfolge zur Auswertung der beiden Listen 175 -** 0 (Standardwert) = Alle OUs werden ausgelesen und alle OUs, die nicht einbezogen werden sollen, müssen in der OuDenyList eingetragen werden. Rekursiv darunter liegende OUs werden dann ebenfalls nicht berücksichtigt. Sollen diese berücksichtigt werden, so müssen sie in die OuAllowList eingetragen werden 176 -** 1 = Keine OUs werden ausgelesen und es müssen explizit alle OUs in der OuAllowList angegeben werden, die einbezogen werden sollen. Sollen bestimmte, darunter liegende OUs nicht mit einbezogen werden, so müssen diese in der OuDenyList eingetragen werden. 175 +To do this, first save the entries you entered in Configuration Manager. Now open the Configuration.xml file, which you can find in the //Aagon/Configuration// directory. 177 177 177 +Using the XML tags <OuAllowList>, <OuDenyList>, and <OuRuleOrder>, you can specify from which OUs computer objects should be imported. The various XML tags have the following functions: 178 + 179 +* <OuAllowList> - List of all OUs to be read 180 +* <OuDenyList> - List of all OUs not to be read 181 +* <OuRuleOrder> - Order in which the two lists are evaluated 182 +** 0 (default value) = All OUs are read, and any OUs that are not to be included must be entered in the <OuDenyList>. Recursively nested OUs are then also excluded. If these are to be included, they must be entered in the OuAllowList 183 +** 1 = No OUs are read, and all OUs to be included must be explicitly specified in the OuAllowList. If certain nested OUs are not to be included, they must be entered in the OuDenyList. 184 + 178 178 {{aagon.infobox}} 179 -OUs m üssenin derSchreibweisedes Distinguished Name (DN) angegebenwerden(sieheBeispiel).BeachtenSiebeim BearbeitenderConfiguration.xml-DateidieGroß-undKleinschreibung,ansonstenwirddiegesamteKonfigurationsdateialsfehlerhaftangesehen undder Dienstbeendet sichdirektnachdemStarten wieder.186 +OUs must be specified using the Distinguished Name (DN) notation (see example). When editing the Configuration.xml file, be sure to use the correct case; otherwise, the entire configuration file will be considered invalid, and the service will exit immediately after starting. 180 180 {{/aagon.infobox}} 181 181 182 - Dasfolgende Beispielsolldas Verhaltenillustrieren:189 +The following example illustrates this behavior: 183 183 184 184 {{code}} 185 185 <OuAllowList> ... ... @@ -202,18 +202,20 @@ 202 202 203 203 (% class="box" %) 204 204 ((( 205 -**E rklärungdesBeispiels:**GrundsätzlichsindalleOUsverboten,dadie RuleOrderauf1 gesetztist.Durch die AngabeeinerOU inderOuAllowList wirddie OU„Aagon“und alleunter ihr liegendenOUs erlaubt.Durch AngabederOU„Marketing“wirddiesespezielleOUwiederausgeschlossen.212 +**Explanation of the example:** By default, all OUs are prohibited because RuleOrder is set to 1. Specifying an OU in the OuAllowList allows the OU “Aagon” and all OUs under it. Specifying the OU “Marketing” excludes this specific OU again. 206 206 ))) 207 207 208 -= Agentless Scanner aktualisieren = 209 209 210 -Nach der Installation eines ACMP Updates kann es vorkommen, dass eine Aktualisierung des Agentless Scanners erforderlich ist 211 211 217 += Update the Agentless Scanner = 218 + 219 +After installing an ACMP Update, you may need to update the Agentless Scanner 220 + 212 212 {{aagon.infobox}} 213 - Siekönnenaus denACMP Release Notesentnehmen,obundwelcheZusatzkomponentenvonIhnen aktualisiertwerdenmüssen.222 +You can check the ACMP Release Notes to see if you need to update any additional components, and if so, which ones. 214 214 {{/aagon.infobox}} 215 215 216 - SollteeineneueVersionvomAgentless Scanner imACMPUpdatevorhandensein,können Sie Ihre vorhandene Installationwiefolgt aktualisieren:225 +If a new version of the Agentless Scanner is available in the ACMP update, you can update your existing installation as follows: 217 217 218 -1. Navig ierenSiezum Installationsverzeichnisdes ACMP Serverszum OrdnerInstallers/AgentlessScanmitderInstallationsdatei ACMP Agentless Scanner_Installer.exe.219 -1. Fol genSieden[[Installationsanweisungen>>doc:ACMP.610.ACMP-Solutions.Client-Management.Agenteninstallation.WebHome||anchor="HAgentlessScannerkonfigurieren"]]und installierenSieallefünfKomponenten.227 +1. Navigate to the ACMP Server's installation directory and open the Installers/AgentlessScan folder, which contains the installation file ACMP Agentless Scanner_Installer.exe. 228 +1. Follow the [[installation instructions>>doc:ACMP.610.ACMP-Solutions.Client-Management.Agenteninstallation.WebHome||anchor="HConfiguringtheAgentlessScanner"]] and install all five components.

