Alerting on changes to a client's installed software?

The retail company I work for is using SCCM (now on R2) to manage our point-of-sale terminals, which run Windows Embedded 7.  With all of the recent data breaches making headlines in the retail space, I have been asked by my superiors to evaluate the
use of SCCM to generate a baseline for the software configuration of one of these systems, and generate alerts upon any unauthorized changes. 
My initial reaction is to say that this would be impracticable at best in SCCM - that we would need to rely on the hardware inventory cycles, but would need to run some extensive custom scripting to actually do the comparison and generate the alerts, and
even if we made it work it wouldn't be real-time which would make it useless for this scenario, and that we'd be better off using SCOM to do this.  But I wanted to put the question out there and see if anyone with more experience had a different point
of view.
Any Thoughts?

Jeremy,
You are right that ConfigMgr is not designed to be a real time monitoring system, especially for these kinds of changes.  If the purpose of monitoring for changes is to improve security, you'll need to look to a software solution designed to do file
system monitoring (TripWire, Splunk, and BeyondTrust all of solutions like this).
However, if they really just want something that tells them if Add/Remove Programs changes from the baseline, you certainly could use ConfigMgr's Compliance to make the clients report often (every hour?) and email reports compliance reports on a schedule.
I hope that helps,
Nash
Nash Pherson, Senior Systems Consultant
Now Micro -
My Blog Posts
If you've found a bug or want the product worked differently,
share your feedback.
<-- If this post was helpful, please click "Vote as Helpful".

Similar Messages

  • Problem with client P6 install

    I installed P6 project client and server on a workstation and server and they work ok. However when i attempted to perform a import i got the error below:
    The problem is that the default port 1433 being used on the client is wrong.
    When i go to help-> About Primavera ->system, i see :
    BRE Database: com.microsoft.sqlserver.jdbc.SQLServerDriver, jdbc:sqlserver://FYITESTSVR:1433;database=PMDB_P6V7; (, 7.0, INTERNAL_PLUGINS)
    But on the server, the TCP/TP properties , "TCP dynamic ports" is set to port 3574
    The strange thing is i did the client install on the server,to test, and the app is using the port 3574.
    Am i missing a step in the client install on a workstation, that requires you set the correct port? Can you port be changed on the client side?
    thanks for the help
    Kes
    com.microsoft.sqlserver.jdbc.SQLServerException: The TCP/IP connection to the host FYITESTSVR, port *1433* has failed. Error: "Connection refused: connect. Verify the connection properties, check that an instance of SQL Server is running on the host and accepting TCP/IP connections at the port, and that no firewall is blocking TCP connections to the port.".
         at com.microsoft.sqlserver.jdbc.SQLServerException.makeFromDriverError(SQLServerException.java:170)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.connectHelper(SQLServerConnection.java:1049)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.login(SQLServerConnection.java:833)
         at com.microsoft.sqlserver.jdbc.SQLServerConnection.connect(SQLServerConnection.java:716)
         at com.microsoft.sqlserver.jdbc.SQLServerDriver.connect(SQLServerDriver.java:841)
         at java.sql.DriverManager.getConnection(Unknown Source)
         at java.sql.DriverManager.getConnection(Unknown Source)
         at com.primavera.infr.db.PrivUserResolver.<init>(PrivUserResolver.java:102)
         at com.primavera.infr.admin.CfgAccessMgr.a(CfgAccessMgr.java:101)
         at com.primavera.infr.admin.CfgAccessMgr.<init>(CfgAccessMgr.java:78)
         at com.primavera.integration.app.importexport.ImportExportAction.do(Unknown Source)
         at com.primavera.integration.app.importexport.ImportExportAction.for(Unknown Source)
         at com.primavera.integration.app.importexport.ImportExportMain.main(Unknown Source)

    Thanks a mil.
    according to note 913032.1 , i ran the following command and fixed the problem with importing.
    INSERT into SETTINGS (namespace, setting_name, setting_value) values ('Administrator_Settings', 'JdbcConnectionURL', 'jdbc:sqlserver://FYITESTSVR:3574;database=PMDB_P6V7;');
    Didn't even realize the claim digger app was not working. That was fixed too.
    thanks

  • Alert Server running on different client

    Hi Techies,
    I have an Alert Categoryt (CAT1) defined in client Dev 100, and the Inbound Abap Proxy Code is executing in Dev 400. I want to trigger an Alert on some event by using the Category(CAT1 defined in 100).
    For this I have used RFC destination from 400 to 100 in the Proxy.  I see Alert in RWB Alert inbox , but no container variable filled?
    What could be the problem?

    Hi Markus,
    I  have chekced the parameter rdisp/btcname in DEFAULT profile and it is pointing to the database server.
    Is this the reason for not running batch job on database server ? If I have to run on Database server, should I change the settings ? or is there any other alternate to resolve this issue.
    Thanks in advance for the help and support.
    Take care
    Best Regards,
    CK

  • Cumulative Update 3 client update install failed with code 1642

    We have SCCM 2012 R2 and recently updated to CU3
    Existing client is version 5.00.7958.1000
    Pushing update package created during CU3 update failing on some computers
    I am trying to update some of laptops using CU3 x86 update and getting following errors
    Script for Package:ABC00126, Program: Cumulative update 3 - x86 client update install failed with exit code 1642
    I have reviewed many forms but couldn't find relevant.
    Update works on about 70% on machines with same image but failed on rest with same 1642 error
    Same issues occurs applying client on during TSequence on some of machines.
    It is very inconsistent,
    Any help would be greatly apprciated
    Thanks
    RJ
    RJ09

    I verified package does copied over in ccmcache folder.
    Also try to run update package using pstools, got error same as Torsten mentioned.
    Here are logs from client.
    Checking content location C:\Windows\ccmcache\gt for use
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Successfully selected content location C:\Windows\ccmcache\gt
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Executing program as a script execmgr
    13/01/2015 6:56:04 PM 2588 (0x0A1C)
    Found executable file msiexec.exe with complete path C:\Windows\system32\msiexec.exe
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Successfully prepared command line "C:\Windows\system32\msiexec.exe" /p configmgr2012ac-r2-kb2994331-i386.msp /L*v C:\Windows\TEMP\configmgr2012ac-r2-kb2994331-i386.msp.LOG /q REINSTALL=ALL REINSTALLMODE=mous
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Command line = "C:\Windows\system32\msiexec.exe" /p configmgr2012ac-r2-kb2994331-i386.msp /L*v C:\Windows\TEMP\configmgr2012ac-r2-kb2994331-i386.msp.LOG /q REINSTALL=ALL REINSTALLMODE=mous, Working Directory = C:\Windows\ccmcache\gt\
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Created Process for the passed command line
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Raising event:
    [SMS_CodePage(437), SMS_LocaleID(1033)]
    instance of SoftDistProgramStartedEvent
    AdvertisementId = "ABC212D1";
    ClientID = "GUID:f298da2e-dfd1-428e-8b3c-b03602f95719";
    CommandLine = "\"C:\\Windows\\system32\\msiexec.exe\" /p configmgr2012ac-r2-kb2994331-i386.msp /L*v C:\\Windows\\TEMP\\configmgr2012ac-r2-kb2994331-i386.msp.LOG /q REINSTALL=ALL REINSTALLMODE=mous";
    DateTime = "20150114005604.541000+000";
    MachineName = "DH-07";
    PackageName = "ABC00126";
    ProcessID = 3496;
    ProgramName = "Cumulative update 3 - x86 client update install";
    SiteCode = "abc";
    ThreadID = 2588;
    UserContext = "NT AUTHORITY\\SYSTEM";
    WorkingDirectory = "C:\\Windows\\ccmcache\\gt\\";
    execmgr
    13/01/2015 6:56:04 PM 2588 (0x0A1C)
    Raised Program Started Event for Ad:ABC212D1, Package:ABC00126, Program: Cumulative update 3 - x86 client update install
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Raising client SDK event for class CCM_Program, instance CCM_Program.PackageID="ABC00126",ProgramID="Cumulative update 3 - x86 client update install", actionType 1l, value NULL, user NULL, session 4294967295l, level 0l, verbosity 30l
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Raising client SDK event for class CCM_Program, instance CCM_Program.PackageID="ABC00126",ProgramID="Cumulative update 3 - x86 client update install", actionType 1l, value , user NULL, session 4294967295l, level 0l, verbosity 30l
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    MTC task with id {8EB498C5-71D5-4933-BA80-6EEB8E189F98}, changed state from 4 to 5
    execmgr 13/01/2015 6:56:04 PM
    2588 (0x0A1C)
    Program exit code 1642 execmgr
    13/01/2015 6:56:04 PM 2784 (0x0AE0)
    Could some please review and advise..
    Thanks
    RJ09

  • How do I install software w/out change to graphic / video settings

    Installing software changes ALL my graphic and video settings, screwing up how I view video, my photo viewing / editing capabilities, and rendering jpeg files in MS Word documents unavailable (they are visible on the monitor but won't print out, can't change attributes).
    Note: I had to restore my computer to a date prior to my first install attempt, rather than just uninstalling.
    I tried reinstalling, unchecking the three default boxes during setup. That did not eliminate the problem. Again, I had to restore my computer to an earlier setting, rather than just uninstalling the software.
    I don't want to use Quicktime to view video streaming.
    Any suggestions?
    iPod Nano 4GB   Windows XP  
      Windows XP  

    You can restore to the latest available software.

  • How do I change platform for downloading and installing Photoshop Elements from Windows to Mac?

    How do I change platform for downloading and installing Photoshop Elements from Windows to Mac?

    As long as your license supports both platforms you should only have to download the Mac version and install/activate using your serial number.  If you need help finding a link to download the file, please indicate the PSE version you need.

  • Attempt to load Oracle client libraries threw BadImageFormatException. This problem will occur when running in 64 bit mode with the 32 bit Oracle client components installed.

    Hello guys,
                Problem has been solved -
    Attempt to load Oracle client libraries threw BadImageFormatException. This problem will occur when running in 64 bit mode with the 32 bit Oracle client components installed.
    1. If you install 64 bit oracle this is not an issue. Install 64 bit oracle.
    2. Download odp.net 32 bit  from below link:-
        ODP.NET Managed Driver Beta Download&lt;/title&gt;&lt;meta name=&quot;Title&quot; content=&quot;ODP.NET Managed Driver B…
    3. installed the odp.net.
    4. open the visual studio 2010.
    5.Select new - project - asp.net web application - project name -ok
    6.select tools- > connect to database- then follow the following steps
                             i>  user name - your user name/client username (example -- hr)
                             ii> password -- enter your password/client password  (example- hr)
                            iii>select connection type -- if you want to connect client database then- select EZ connect other wise select tns
                            iv>test the connection- then you will get connection succeed.
                            v> then click ok
    Thanks
    Chandrashekhar

    You do not need to do anything in VS.  You do need to configure both tnsnames.ora files, because the drivers do not share any data.
    Please see:
    http://sqlblog.com/blogs/jorg_klein/archive/2011/06/09/ssis-connect-to-oracle-on-a-64-bit-machine.aspx

  • This problem will occur when running in 64 bit mode with the 32 bit Oracle client components installed.

    hi friends ,
    My report Fetch from the orcle database , we installed Oracle 10g and 11g - clent 32 -bit on win 2k8 -64 bit machine .while design time runing fine,but ofter depolyement im facing below issue.
    In error has occurred during report processing. (rsProcessingAborted)
    The execution failed for the shared data set 'abc'. (rsDataSetExecutionError)
    Cannot create a connection to data source ' Data source for shared dataset'. (rsErrorOpeningConnection)
    Attempt to load Oracle client libraries threw BadImageFormatException. This problem will occur when running in 64 bit mode with the 32 bit Oracle client components installed.
    An attempt was made to load a program with an incorrect format. (Exception from HRESULT: 0x8007000B)
      Any help is greatly appreciated, I have tried couple of solutions going through some threads online but no use and place dt tell install 1og r 11g 64-bit

    Hi,
    Based on the error message, we should confirm whether Oracle client tool has been installed on the Report Server at the beginning. If the Report Server installed is 64-bit, we should also install a 64-bit Oracle client tool on the Report Server. Besides, we
    can also try to bypass tnsnames.ora file when connecting to Oracle by specifying all the information in the data source instead of using the TNS alias to connect
    to the Oracle database. Please see the sample below:
    Data Source=(DESCRIPTION=(CID=GTU_APP)(ADDRESS_LIST=(ADDRESS=(PROTOCOL=TCP)(HOST= server01.mydomain.com)(PORT=1521)))(CONNECT_DATA=(SID=OracleDB)(SERVER=DEDICATED)));
    Reference:http://blogs.msdn.com/b/dataaccesstechnologies/archive/2010/06/30/ora-12154-tns-could-not-resolve-the-connect-identifier-specified-error-while-creating-a-linked-server-to-oracle.aspx
    Hope this helps.
    Regards,
    Heidi Duan
    Heidi Duan
    TechNet Community Support

  • Change default BW Client

    Hello All,
          I want to change my existing default BW client XYZ in system ABC to another client which already exists viz., MNO.
    The System in Netweaver 04.
    SAP_BW Release is 350, Patch level is 0009
    BI_CONT Release is 352, Patch lebel is 004
    Database is  Oracle 9 on Win Server 2003 server.
          Please do suggest me the steps and precautions to be taken before proceeding.
    Thank you All,
    Bob

    Hi Bob,
    Default client as default login client or as RFC connection???
    Change default login client at RZ10 parameter login/system_client
    if you're talking about RFC connection just go to SM59 in the target system and change the client for the BW RFC connection...
    You may want to give us more details.
    Regards
    Juan
    Please reward with points if helpful

  • Anyconnect client problem, load balancing fqdn changes after update client?

    Hi,
    We use two asa's in loadbalancing. Users use the loadbalancing fqdn name to connect. This works fine until we push new client anyconnect software, that the connect to field changes from the fqdn to the appliance ip address where the client downloaded the software. So loadbalancing will not work anymore. Is there a solution for this?
    Thx,
    Marc

    This sounds like CSCsz39019:
    http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsz39019
    Symptom:
    Anyconnect client preserves the FQDN name of the ASA its connecting to instead
    of load-balancing cluster FQDN.
    Workaround:
    When the cluster member appears in the host list, user can select the correct
    host by clicking the drop down. The next time user starts the client, the
    cluster member will no longer be visible. It will have been replaced with the cluster name last selected.
    This should be fixed in 2.3(2028)
    2.4(192) and 2.5(53) or any higher release. Keep an eye out for the next release with this fix.

  • Getting ROracle run when 32 bit and 64 bit clients are installed

    Hello all,
    I am using RStudio with R 3.01 (64-bit) on a Windows 7 64 bit installation. I am able to load ROracle when only the 64 bit Oracle Client is installed.
    Unfortunately I have to use the 32 bit client for another programme.
    After I have installed both clients I can't load the ROracle library anymore in R.
    The error message is:
    Error in inDL(x, as.logical(local), as.logical(now), ...) :
      unable to load shared object 'C:/Program Files/R/R-3.0.3/library/ROracle/libs/x64/ROracle.dll':
      LoadLibrary failure:  %1 ist keine zulässige Win32-Anwendung.
    Error: Laden von Paket oder Namensraum für ‘ROracle’ fehlgeschlagen
    I have set both paths in my environment:
    "C:\oracle\product\11.2.0\client_1\bin;C:\oracle\product\11.2.0\client_2\bin;"
    Could anybody give me a hint what could I try to get it running?
    Kind regards,
    Uli

    Hi Uli,
    In addition to adding the 64-bit Instant Client to PATH, did you set the environment variable OCI_LIB64 to the location of 64-bit libraries?
    See the ROracle INSTALL instructions for details:
    http://cran.r-project.org/web/packages/ROracle/INSTALL
    Also see the step-by-step instructions for configuring the Oracle Instant Client for use with ROracle (and ORE) in the Oracle R Enterprise Installation Guide.
    Regards,
    Sherry

  • Best Way to Change Source System Client

    We initially had a ECC source client for BI as 35.  But over time, we suffered with good test data because the ECC team use client 15 and not 35.  We want to change BI 7 to use client 15.  I have created a new source system in RSA1 for Client 15 but when I try to delete client 35 and /or change the source client on a datasource, all the data mappings are deleted!
    I would really appreciate any advice or information on the best way to change the source R3 client for Bi without losing data mappings.  Point awarded and much respect
    Warm regards
    Lee Lewis

    Hi,
    Yes. There is a way to change the source system without deleting the old system. Please use the T.code BDLS and for more information refer the below link
    Re: Changing a Source System.
    OSS note 886102 will also give more information about this.
    Hope it helps.
    Thanks.

  • How can i change the full download and install path because my C: ist full and it automaticly downloads it on C: i allready changed in on adobe creative cloud but it dont work

    How can i change the full download and install path because my C: ist full and it automaticly downloads it on C: i allready changed in on adobe creative cloud but it dont work

    Read the part about SSDs. Otehrwise there is nothing you can do. Certain components wil lalways install on your system root drive.
    Mylenium

  • How to judge whether  the client  has installed AcrobatReader?

    How to judge whether the client has installed AcrobatReader?

    Hi,
    first check the client copy log using scc3->all clients
    under target client you can identify which client is generated by client copy.
    the remaining client is only created using SCC4 ( exclude 000,001,066 )
    regards,
    kaushal

  • Adding sql loader into 11g Client already installed

    I have already installed Oracle 11g client and need to add in sql loader. How is that best accomplished?

    Easier than I thought. Just go back into the previous oracle client home install and the preinstalled items will be greyed out. Just add additional components you want to install.

Maybe you are looking for

  • How to Import pictures in iphoto on ipad with original name

    How to import pictures into iphoto on my ipad air with the original filenames. IT now Seems my pictures get a new name.

  • Converting Blu-Ray

    I was wondering if anyone knows if it is possible to convert Blu-Ray to MKV in Arch? Would save me spending time in Windows 7 if I can do it in Arch. I can don't mind pre-ripping it to m2ts in Windows but it takes so long it would be nice ti be able

  • Setting up web server

    I have Sun Web Server running on one of my local PC's (192.168.1.136, port 136). I can access the web server from one of my other local PC's by typing 192.168.1.136:136 in my web browser. However, I can not access it by typing my external IP xxx.xxx.

  • UCS Management Pack for System Center 2012 OpsMgr add monitor wizard error

    We're successfully using the 2.6.0.179 version of the UCS Management Pack for System Center 2012 Operations Manager in our 2012 SP1 OpsMgr environment; however, in the new 2012 R2 OpsMgr environment we've stood-up and in which we installed the 2.6.2.

  • Does someone know how big a compilated .ipa can get before crashing on an iPad 4?

    Hello! I remember the Apps on the iPad 1 crashing above a size around 400 MB and now i wonder if someone already discovered a "maximum" size for the .ipa on iPad 4. We already have a size around  370 MB and there is still lots of content that needs t