29 February 2008

issue with 29/02/2008

KNOWN ISSUE: Viewing Software Delivery Tasks displays a System.ArgumentOutOfRangeException error
Note: If you are experiencing this particular known issue and wish to be notified of changes in the status of this issue, please subscribe to the article by clicking to the right of this article. As the status of this request is updated, subscribers will be notified of any changes and decisions that are made.
Problem/Symptoms
When attempting to view Software Delivery Tasks in the NS Console, the following error is displayed in the console:
System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values.Parameter name: Year, Month, and Day parameters describe an unrepresentable DateTime. at System.DateTime.DateToTicks(Int32 year, Int32 month, Int32 day) at Altiris.NS.SoftwareDelivery.UI.advGeneral.LoadAdvertisement() at Altiris.NS.SoftwareDelivery.UI.advGeneral.Page_PreRender(Object sender, EventArgs e) at System.Web.UI.Control.OnPreRender(EventArgs e) at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Control.PreRenderRecursiveInternal() at System.Web.UI.Page.ProcessRequestMain()
The date today is February 29 2008, which is a leap year.
Cause
This issue may appear when it is a leap year as the default removal date is calculated by adding a year on to today's date -- for example, if today is February 29 2008, the default removal date is calculated to be February 29 2009 which does not exist.
This is a problem in the Altiris.NS.SoftwareDelivery.UI.dll.
Resolution
The following hot fix only installs on version 6.1.1058 SP3:
Hotfix Altiris_SoftwareDelivery_6_1_SP3_KB40682.exe is available for this issue and can be found at:
http://www.solutionsam.com/solutions/Hotfixes/Altiris_SoftwareDelivery_6_1_SP3_KB40682.exeInstallation Steps:Run Altiris_SoftwareDelivery_6_1_SP3_ KB40682.exe to install the Software Delivery Solution KB40682.Uninstall Steps:From Add/Remove Programs: Click the Remove button in the Add/Remove Programs dialog box to uninstall Altiris_SoftwareDelivery_6_1_SP3_ KB40682.KB40682 supersedes the KB35826 and KB37620. Installing the KB35826 after installation of this KB40682 will overwrite the prior DLL version to be stored in the Software delivery / bin folder.
For other versions of SWD, the following work around should be employed:

As a workaround, the customers could define valid expiry dates for all of the SWD tasks that they wish to view/edit in the NS Console by exporting and editing the XML definition of the SWD task and reimporting it.

They need to look for:



And change it to something like:



If the before attribute is present and the date valid, then the task will open successfully.
NOTE: On the task, do NOT make the availability date for today as you will run into this bug again

09 February 2008

Agent security vulnerability corrected

The agent security vulnerability is covered in R7 : https://kb.altiris.com/article.asp?article=35803&p=1

The vulnerability from Symantec : http://securityresponse.symantec.com/avcenter/security/Content/2008.02.06.html

Release Notes for Altiris® Notification Server™ 6.0 SP3 R7

Rollup 7 (R7) for Notification Server 6.0 is a rollup of fixes to the core product since the release of Service Pack 3. It includes R1 (KB22690), R2 (KB23784), R3 (KB25133), R4 (KB27859), R5 (KB31946), and R6 (KB34317)

This release covers Agent security vulnerability corrected http://securityresponse.symantec.com/avcenter/security/Content/2008.02.06.html

Read more : https://kb.altiris.com/article.asp?article=35803&p=1

Automated Installation Kit (AIK) for Windows Vista SP1 and Windows Server 2008

The Windows Automated Installation Kit (Windows AIK) is designed to help corporate IT professionals customize and deploy the Windows Vista and Windows Server 2008 family of operation systems.

This you need for DS 6.9

06 February 2008

vLite 1.1.1

Here is the quick fix for the specific issue regarding SP1 MS preintegrated installation modification when running vLite from Windows XP. Some users reported a Registry Load error popup at the last vLite step in that scenario.If you are running vLite from Windows Vista then this update isn't crucial but still recommended. Thank you for the prompt reaction before the preintegrated SP1 goes public.

vLite is a tool for customizing the Windows Vista installation before actually installing it.Main features are:
hotfix, language pack and driver integration
component removal
unattended setup
tweaks
split/merge Vista installation CDs
create ISO and burn bootable CD/DVD Windows Vista from Microsoft takes a lot of resources, we all know that. vLite provides you with an easy removal of the unwanted components in order to make Vista run faster and to your liking.This tool doesn't use any kind of hacking, all files and registry entries are protected as they would be if you install the unedited version only with the changes you select.It configures the installation directly before the installation, meaning you'll have to remake the ISO and reinstall it. This method is much cleaner, not to mention easier and more logical than doing it after installation on every reinstall.

14 January 2008

KNOWN ISSUE: Deployment Server Win32 console security does not properly pass through authenticate users from AD groups

KNOWN ISSUE: Deployment Server Win32 console security does not properly pass through authenticate users from AD groups

Problem/Symptoms

When the Deployment Server Win32 console security is enabled with imported AD group, and a user attempts to log into the console (using AD pass through authentication), they are prompted for credentials. If they do not enter the credentials it will open the console with no security rights. If they do enter in their proper credentials it opens the console with all security rights that the user should have. It also creates a new security user in the Deployment Solution console security instead of just using the group membership.

There are multiple types of environments that can cause this behavior. The following are 3 different known scenarios that exhibit this behavior:

Scenario 1

  1. AD environment is set up as follows: There are two domain controllers, "parent.com", and "child.parent.com" which is a child domain of "parent.com".
  2. A security group is added to "child.parent.com" domain called "Console Users".
  3. A domain user is created called "Altiris" and is added to the "Console Users" group.
  4. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
  5. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
  6. Log onto a computer that has a Win32 console installed using the account AD "Altiris" from the "child.parent.com" domain.
  7. Notice how the console security prompts for the username and password. Enter that information and continue.
  8. From the console select Tools > Security and notice how that user ("Altiris@child.parent.com") is now listed as a security user even though it was never added directly, but only through AD group membership.

Scenario 2

  1. AD environment is set up as follows: There is one domain controller, "company.com", which was given a NETBIOS name of "MYCOMPANY" (which is different than the UPN domain name).
  2. A security group is added to "company.com" domain called "Console Users".
  3. A domain user is created called "Altiris" and is added to the "Console Users" group.
  4. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
  5. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
  6. Log onto a computer that has a Win32 console installed using the account AD "Altiris" from the "company.com" domain.
  7. Notice how the console security prompts for the username and password. Enter that information and continue.

Scenario 3

  1. AD environment is set up as follows: There is one domain controllers, "company.com", which is set up with default settings (where the NETBIOS name is "COMPANY" which is default).
  2. A security group is added to "company.com" domain called "Console Users".
  3. The domain user "Administrator" is added to the "Console Users" group.
  4. The domain user account of "Administrator" does not have the UPN name. Other accounts on the domain controller also might not have a UPN name, but have a SAM name. 
  5. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
  6. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
  7. Log onto a computer that has a Win32 console installed using the account AD "Administrator" from the "company.com" domain.
  8. Notice how the console security prompts for the username and password. Enter that information and continue.
  9. From the console select Tools > Security and notice how that user ("Administrator@") is now listed as a security user even though it was never added directly, but only through AD group membership.

Cause

The original express.exe from DS SP2 build 378 was incorrectly caching the NETBIOS domain name in the database. Because the users were cached incorrectly they were not being identified by Active Directory.

Resolution

Solution:

1) Backup Express database and express.exe: Backup the database - usually named 'express' - before making any changes.  Make a copy of express.exe.
2) Remove improperly cached users:  Users who have attempted to login to the Deployment Console with security enabled prior to this fix will have users incorrectly cached in the database.  These users must be removed from the securityuser table. To remove these users run the following query against the SQL server:

DELETE FROM securityuser WHERE ad_user = 1 AND user_guid = ''
3)  Replace Express.exe:  Replace the original express.exe included in SP2 with the express.exe attached to this knowledgebase article. 
4) Appy License to Express.exe:  Open the license tool under your Deployment Server program files directory. (License.exe) Run the tool to license the express.exe with all applicable licenses.


Note 1:
  This executable has been through the official Symantec Hotfix process and is supported by Symantec Support Services.

Note 2:  No services need to be stopped to affect this change. Only verify that console users have closed any remote sessions to the console. For locally installed consoles, this exe will need to be deployed via DS or NS once licensed.

Note 3: Changes made to express.exe in KB 38727 are also included in the express.exe attached to this KB.

13 January 2008

What is the best way to replicate the Altiris Solutionsam web site?

Question
Our NS Servers don't have internet access. What is the easiest way to replicate the contents at SolutionSam to a local directory and keep it current without having to manually down the solutions?
Answer
Solutions are only maintained on
www.SolutionSam.com/solutions/6_0. Some customers utilize a shareware product called HTTrack.. HTTrack can be used to mirror the SolutionSam site to a common local directory. It will update any changes made on www.SolutionSam.com/solutions/6_0 to the local directory automatically.http://www.httrack.com/

11 January 2008

Scripts used to manage collections

Question
How can I find the following information about collections on a Notification Server?
The total number of dynamic and static collections.
A list of the dynamic and static collections by name.
A list of collections that have not been updated in over 7 days.
A list of collections that do not have any policies linked to them.
Answer
Displays Collections that Do not Have Policies Applied
select name [Collections without assigned policies] from vcollection where guid not in (select childitemguid from itemreference where hint like 'policyappliestocollection') and classguid like 'B8B666E1-FED3-4482-8D5A-0895658317B2' and attributes & 1 <> 1order by name asc
Collections not Updated in the Last Week

  • select i.name [Collection Name], c.lastupdated [Date Last Updated], i.classguidfrom item i join collection c on i.guid = c.guid where c.lastupdated <> 1order by i.name asc

Displays Static Collection Names

  • select Name [Static Collections] from item where classguid like 'B8B666E1-FED3-4482-8D5A-0895658317B2'and state like '%true%'and attributes & 1 <> 1order by name asc

Displays Dynamic Collection Names

  • select Name [Dynamic Collections] from item where classguid like 'B8B666E1-FED3-4482-8D5A-0895658317B2'and state like '%false%'and attributes & 1 <> 1order by name asc

Displays a Static Collection Count

  • select count(*) as name from item where classguid like 'B8B666E1-FED3-4482-8D5A-0895658317B2'and state like '%true%'and attributes & 1 <> 1

Displays a Dynamic Collection Count

  • select count(*) as name from item where classguid like 'B8B666E1-FED3-4482-8D5A-0895658317B2'and state like '%false%'and attributes & 1 <> 1

Excluding/Controlling what Client MAC is reported to the DS Server

Problem/Symptoms
Many computers have multiple NICs, which can cause problems in Deployment Solution. For instance, a computer may only have one NIC connected, and Deployment Solution may report on the second NIC with no IP address, thus showing a missing IP address in the console. Clustered computers may have a single assigned MAC given to multiple computers, again causing problems within Deployment Solution if the incorrect MAC is tracked.Computers reporting multiple NICs may also encounter Deployment Server licensing issues when each NIC is assigned a separate license.
Cause
Because DS tracks a computer based only on a single NIC/MAC address, sometimes human intervention is necessary to prevent conflicts or incorrect data.
Resolution
A CustomData.ini file can be created to exclude NICs or MACs so that DS will only track the remaining NIC/MAC option. This file is created by duplicating the Dynamic.ini file, and renaming the duplicate to CustomData.ini. This can either be performed on the client computer directly, or on the server and then sent out with a job to the client computers.
First, be sure there is a [Filters] section in this file.
Since DS combines the contents of both the Dynamic.ini and CustomData.ini files, the CustomData.ini file does not need to have all the same information as the Dynamic.ini. However, for this exercise, at least the [Filters] section is required.
In this section, a line may be modified (or created) with "FilteredAdapterNameList" to include custom/unique types of adapters which should be excluded or ignored by DS (such as dial-up adapters, or WiFi adapters). The line should look something like this:


  • FilteredAdapterNameList=Dial-Up Adapter,VPN,PPP Adapter
Alternatively, a "FilteredMACAddresses" line may be used to exclude certain the MAC addresses on adapters that may be otherwise legitimate. This would be the case for duplicate NICs, such as having two identical Intel NICs, where the above option would end up excluding both. This line is used to exclude specific MAC addresses, rather than a type of connection. This line should look something like this:


  • FilteredMACAddresses=CCCCCCCCCCCC,FFFFFF000000,00038A000011
Finally, for those who may need it, there is one other way to filter, and that is based on user. By default, we already exclude one user, but you may add others.
The FilteredUserNames line looks like this (additional entries, as with the above options, should be seperated by commas):


  • FilteredUsernames=SMSCliSvcAcct&,IWAM_

Currently, users are required to manually create a CustomData.ini file from a copy of the Dynamic.ini file and enter the MAC addresses of NIC cards that users do not want to register with Deployment Server.

08 January 2008

Inventory Tasks not running on clients

Problem/Symptoms
A large number of clients are not running inventory. The express\inventory folder isn't getting created. Basis inventory is running successfully as are many software delivery tasks.These Inventory tasks are queued but never start.
Environment
Notification Server 6.0 SP3 R2 Inventory Solution 6.1 SP1
Cause
The inventory tasks' priority was changed from Normal to Low in order to give higher priority to Software Delivery tasks. However, because of problems with clients getting the packages to some of these Software Delivery tasks, they never complete. Because the higher priority tasks never completed, the lower priority items could never start.
Resolution
You have the option of resetting the priority of the inventory tasks back to "Normal" so that their priority level is at least equal to the priority of the Software Delivery tasks. The root cause of package downloads failing also needs to be resolved.

06 January 2008

How do I modify AeXMachInv.exe to properly report my processor?

Question
How do I modify AeXMachInv.exe to properly report my processor? Inventory Solution incorrectly identifies my processor as "Intel Compatible".
Answer
The following process can be used to update the ProcessorDesc.ini file to include identification for a processor being labeled "Intel Compatible". This process is provided "as is" and contains no guarantees.
This process requires dbgview.exe, a debug utility from Microsoft, located here:
http://technet.microsoft.com/en-us/sysinternals/bb896647.aspx.
After extracting the utility, launch it so the debug capture window is shown.
Go to Start > Run, type cmd, and click OK.
Browse to the following location: C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache
Type the following Command line and press Enter: AeXMachInv.exe /norbin
The debug window will fill with trace information.
When the launch is complete, search within the trace elements for the word "family". There will be a series of numbers similar to the ones shown in the ProcessorDesc.ini file.

For example:
00 1111 0001 Intel Pentium 4 processor
00 1111 0010 Intel Pentium 4 processor Special
00 1111 0011 0100 Intel Pentium 4 processor

Check against the contents of the ProcessorDesc.ini file to see if the number sequence is already contained therein. The file is contained under \\NotificationServer\NSCap\Bin\Win32\X86\Inventory Solution\.
If it is not, add the number sequence followed by the name of the processor (that is, Intel Pentium M Mobile Processor or AMD Athlon). What you list here is what will be used for the identity of that processor. Note: You should add the sequence and identifier under the proper category (Intel's the first section, AMD the second, and so on).
Save the file. Once saved, you can manually update the Distribution Point for the package so the changes in the file are detected and the file is updated on the target client computers, or wait for it to automatically update. The next time Inventory runs, the new entry will be used using the identifier provided.

Active Directory Synchronization doesn't appear to be working 6.1

Problem/Symptoms
Computers that are deleted from Active Directory are not being deleting from the Notification Server database.
Cause
There can be several reasons that computers may not be deleted from the Notification Server database after being removed from Active Directory.
If the computer is set to a status other than Active, it will not be removed.
If the Import Rule that the computer was deleted with no longer exists, the computer will not be removed.
If the computer was never imported by the Microsoft Active Directory Component, it will not be removed.
If the computer shows that it has been deleted in the ItemResource table.
Directory Synchronization does not remove computers that are managed; it lets Purge Maintenance take care of those computers.
Resolution
Run the following SQL to determine the reason that the computers are not being deleted then do the appropriate action to correct it.

Select i.guid, i.name as 'Computer Name', 'Reason' = Case When ra.ResourceAssociationTypeGuid = '3028166F-C0D6-41D8-9CB7-F64852E0FD01'and childresourceguid not like '0A0203A5-D2B6-49F1-A53B-5EC31A89437C'Then 'Computer is not active'When i.guid in(select ii._resourceguidfrom inv_import_rule_imported_items iijoin item i on i.guid = ii._resourceguidwhere _resourceguid not in(select _resourceguidfrom inv_import_rule_imported_itemswhere importruleguid in(select guidfrom itemwhere classguid = 'B2378265-2779-49E6-998D-8BE620B3D9D9'))and i.classguid = '539626D8-A35A-47EB-8B4A-64D3DA110D01') Then 'Import Rule no longer exists' When i.guid not in (select i.guid from item i join inv_import_rule_imported_items ii on ii._resourceguid = i.guid Where i.classguid = '539626D8-A35A-47EB-8B4A-64D3DA110D01') Then 'Computer does not have import information (Generaly means it was not imported)' When i.guid in (select guid from itemresource where deleted = 1) Then 'The resource shows that it has been deleted in the ItemResource table' When i.guid in (Select guid from vcomputer Where ismanaged = 1) Then 'Directory Synchronization does not remove machines that are managed it lets Purge Maintenance take care of those computers.' Else 'This computer WILL be deleted when removed from Active Directory' end from vitem i left join resourceassociation ra on ra.parentresourceguid = i.guid where i.classguid like '539626D8-A35A-47EB-8B4A-64D3DA110D01' order by 'reason'

The resolution will depend on the cause. A report (you can find ite here) can be imported to help simpify the process.
If the computer is set to a status other than Active, it will not be removed. Find the computer in a report or collection and change the status back to Active or Delete it.
If the Import Rule that the computer was deleted with no longer exists, the computer will not be removed. Run the resolution in article
1815 to associate the computer with a current rule or delete it from the report.
If the computer was never imported by the Microsoft Active Directory Component, it will not be removed. Wait for Purge Maintenance or manually delete the computer.
If the computer shows that it has been deleted in the ItemResource table. Manually delete the computer from a report or collection.
Directory Synchronization does not remove computerss that are managed; it lets Purge Maintenance take care of those computers. Wait for Purge Maintenance or manually delete the computers.
If there is a problem with the schedule it may also help to disable and renable the Directory Synchronization task through the Altiris console.
Upgrading to the Microsoft Active Directory Component 6.1.x Resolves this problem if a previous version is currently installed.


Thx Gert

05 January 2008

Fixing the Owner of DB Objects

Depending on the way you have your SQL database security set up you may end up with stored procedures and other objects having an owner other than dbo. The typical case of this happening is when running the upgrade with an account that is not an SA on the SQL Server.
If unresolved, this naming issue can give you grief. Here's a way to fix it.
This ownership issue will ultimately end up in causing a lot of errors such as the
Deployment Console not opening or certain tasks failing. Basically anything that tries to call the stored procedure will fail because the name is wrong. For example: A stored procedure in the DS database called dbo.del_computer may have its name changed during an upgrade to username.del_computer.


To fix this situation run the following SQL script. Change the USERNAME to whatever the owner is for the objects that need to be changed.DECLARE

@OldOwner sysname,
@NewOwner sysname
SET @OldOwner = 'USERNAME'
SET @NewOwner = 'dbo'
DECLARE CURS CURSOR FOR
SELECT name FROM sysobjects WHERE type = 'p' AND uid = (SELECT uid FROM sysusers WHERE name = ldOwner) AND NOT name LIKE 'dt%' FOR READ ONLY

DECLARE @ProcName sysname
OPEN CURS
FETCH CURS INTO @ProcName
WHILE @@FETCH_STATUS = 0
BEGIN
IF @@VERSION >= 'Microsoft SQL Server 2005'
BEGIN
EXEC('alter schema ' + @NewOwner + ' transfer ' + @OldOwner + '.' + @ProcName)
exec('alter authorization on ' + @NewOwner + '.' + @ProcName + ' to schema owner')
END
ELSE
EXEC('sp_changeobjectowner ''' + @OldOwner + '.' + @ProcName + ''', ''' + @NewOwner + '''')
FETCH CURS INTO @ProcName
END
CLOSE CURS
DEALLOCATE CURS

But this will fix only the Stored Procedures so you need to fix other "types" such as F, V
So run this this querie at least 3 times.

Helpdesk : Customizing The Winuser Console (SP5)

WooHoo! Looks like Helpdesk pro David Falcon spent his holiday break customizing his company's helpdesk. If you've ever wanted to "tune" the forms in your helpdesk or just add your company logo to its pages, read on to follow David's lead at Juice Link

27 December 2007

Dell Optiplex 755 and IBM T61 fails to see the hard drive and connect to Deployment Solution

Environment
Deployment Solution 6.8 SP2Windows PE* 1.5Dell Optiplex 755 with Intel Vpro NIC IBM T61
Intel VPro Certified 82566 DM-2

Cause
SATA controller is not being detected and NIC drivers are not loading.

Resolution
Follow these steps to get the latest drivers from dell for the SATA controller and VPro NIC then modify the WinPE boot:
1. Download the Intel Matrix Storage Manager drivers from here. For Linux download the AHCI drivers through boot disk creator using the internet option when specifying the Nic drivers in the wizard.
2. Follow steps 1–4 from article 19067.
3. Download the Intel 825xx Gigabit Platform LAN Network Device drivers from here. For Linux download the Intel e1000 drivers through boot disk creator using the internet option when specifying the Nic drivers in the wizard.
4. Create or modify a WinPE 32-bit boot (either through boot disk creator or PXE config).
5. Add the NIC driver (e1e5132.inf) and continue through the wizard until the "Boot Options Settings" page and select "factory -winpe" then finish to the end of the wizard.
6. Change the BIOS setting to SATA compatibility from AHCI in the T61 and T61P

20 December 2007

VM to fast to switch to boot order?

Edit your .vmx file and add the line:
bios.bootDelay = "5000"
which adds a 5000 millisecond (5 second) delay to the boot,
**or add**
bios.forceSetupOnce = "TRUE"
to make the VM enter the BIOS setup at the next boot.
(Thx Michael)

19 December 2007

What is the AexAgentUIHost.exe process?

This process hosts the system tray icon for those computers logged onto the NS via terminal services. In addition, you will see one instance of this process for each user logged on to the system.

There is a registry key setting that can keep AexAgentUIHost.exe from loading for each user:

HKLM\Software\Altiris\Altiris Agent\Run UI in main Session only

Changing the value to 1 will keep the process from loading for every user.

Multiple instances of the same filename, but different file path are not reported by Inventory Solution for Windows

Problem/Symptoms

A Software Inventory scan using AeXAuditPls.exe does not report multiple instances of the same file. The Windows* operating system allows files to be named the same as long as they are in separate folders. As determined by inspecting the auditpls.nsi file on a client computer, files with the same name but different file paths are collected properly by AeXAuditPls.exe and sent to the Notification Server. However, only one of these files is added to the AeX SW Audit Software data class.
Cause

The Notification Server dataloader uses the following properties to determine a unique row to be placed into the AeX SW Audit Software data class (Inv_AeX_SW_Audit_Software_spt and Cmn_SW_Common tables in the database):
  • Manufacturer
  • Product Name
  • Product Version
  • Language
  • File Name
  • File Size
  • InternalName
  • File Description

The dataloader will ignore multiple instances of files that match on these properties. Note that "File Path" in not used to determine uniqueness, which is why only one instance of a file that occurs in multiple folders is inserted into the database.

Also note that since "File Size" is used to determine uniqueness, data files (and executable files) with the same name, but with different sizes, will be inserted into the database. On the odd chance that data files with the same name contain different data, but have the same exact size, only one file will be inserted into the database.

Resolution

This resolution is provided "as is" and has not been reviewed by the developers of Inventory Solution for Windows. It may not be suitable for every environment.

Important: Because this resolution updates the data in the database, back up the Altiris database first.

A change to the DataClassAttribute Table will cause the Data Loader to use "File Path" to determine unique rows to insert into the database. The following SQL query will show the attributes the Data Loader uses to determine uniqueness.

USE Altiris
SELECT * FROM DataClassAttribute
WHERE InvClassId = (SELECT id FROM DataClass WHERE Name = 'AeX SW Audit Software')
ORDER BY AttrId

You can use this SQL statement to change the "File Path" attribute so it is used to determine uniqueness.

USE Altiris
UPDATE DataClassAttribute
SET KeyIndex = AttrId, Nullable = 0
WHERE AttrName = 'File Path'
AND InvClassId = (SELECT id FROM DataClass WHERE Name = 'AeX SW Audit Software')

Note: This change may be overwritten if a upgrade or repair is made to Inventory Solution for Windows.

16 December 2007

WINPE2.1, Deployment Server 6.9 and VMWare

ref : link to juice

As we prepare for a new deployment of Deployment Solution 6.9, IT personnel may encounter difficulties using WinPE 2.x in conjunction with VMWare network drivers. In addition, as more and more users try to virtualize their environments, Microsoft Vista users might find themselves without networking in VMWare Virtual Machines.
There is little known work-around for this issue: make the virtual machine load up the Intel e1000 network driver. Forcing this change will make virtual machines think they have an e1000 network driver and load up the network. This also prepares Virtual Machines to run automation jobs in a pre-boot environment using this driver instead of the VMWare drivers.

Note that the minimum requirement for
WinPE 2.0 and 2.1 is 512 megs of ram. If you use less then that you may experience problems that are very similar to driver issues.

Also, in VMware 6.0 if you create a VM and specify it as a Vista machine it will automatically add the e1000 identifier to the nic.

05 December 2007

Procedure to free up Patch Management License for Retired PC's

I used this procedure to free up my license on retired resource for Patch Management KB Ref
  1. Create a folder in the Resource Tab, Resources
  2. Get the GUID of this folder by right clicking on this folder then Properties and copy the GUID for later use
  3. Get the Report from the KB link and import it into Reports
  4. Run this report for Non Active Resources
  5. Select All resource and move them to the newly created folder in step 1
  6. Create a folder on the server where the exported files will reside
  7. Open a command window and type \diagnostics\ImportExportUtil /export {GUID from step 2} ""
  8. When export is complete check if all files are in this directory you created in step 6, if ok then continue.
  9. return to your report from step 4, Select all Non Active resoures and delete them by right clicking and select Delete
  10. Check the license by clicken refresh buttun in Configuration Tab, Licenses
  11. Now reimport the deleted resources by run the following command in the command window on the command prompt \diagnostics\ImportExportUtil /import ""
  12. Rerun the report from step 4 to check if all resources are back.

Example
E:\AExNS\Diagnostics\ImportExportUtil /export {21082ac4-26fe-43e9-a304-98632f65afa5} "e:\RetiredPC"
E:\AExNS\Diagnostics\ImportExportUtil /import "e:\RetiredPC"

KNOWN ISSUE: Deployment Server Win32 console security does not properly pass through authenticate users from AD groups

Problem/Symptoms


When the Deployment Server Win32 console security is enabled with imported AD group, and a user attempts to log into the console (using AD pass through authentication), they are prompted for credentials. If they do not enter the credentials it will open the console with no security rights. If they do enter in their proper credentials it opens the console with all security rights that the user should have. It also creates a new security user in the Deployment Solution console security instead of just using the group membership.

There are multiple types of environments that can cause this behavior. The following are 3 different known scenarios that exhibit this behavior:

Scenario 1

1. AD environment is set up as follows: There are two domain controllers, "parent.com", and "child.parent.com" which is a child domain of "parent.com".
2. A security group is added to "child.parent.com" domain called "Console Users".
3. A domain user is created called "Altiris" and is added to the "Console Users" group.
4. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
5. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
6. Log onto a computer that has a Win32 console installed using the account AD "Altiris" from the "child.parent.com" domain.
7. Notice how the console security prompts for the username and password. Enter that information and continue.
8. From the console select Tools > Security and notice how that user ("Altiris@child.parent.com") is now listed as a security user even though it was never added directly, but only through AD group membership.

Scenario 2

1. AD environment is set up as follows: There is one domain controller, "company.com", which was given a NETBIOS name of "MYCOMPANY" (which is different than the UPN domain name).
2. A security group is added to "company.com" domain called "Console Users".
3. A domain user is created called "Altiris" and is added to the "Console Users" group.
4. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
5. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
6. Log onto a computer that has a Win32 console installed using the account AD "Altiris" from the "company.com" domain.
7. Notice how the console security prompts for the username and password. Enter that information and continue.

Scenario 3

1. AD environment is set up as follows: There is one domain controllers, "company.com", which is set up with default settings (where the NETBIOS name is "COMPANY" which is default).
2. A security group is added to "company.com" domain called "Console Users".
3. The domain user "Administrator" is added to the "Console Users" group.
4. The domain user account of "Administrator" does not have the UPN name. Other accounts on the domain controller also might not have a UPN name, but have a SAM name.
5. Deployment Solution 6.8 SP2 build 378 is installed with all default options.
6. Console security is enabled, and the "Console Users" AD group is given full administrative rights to the Deployment Solution console.
7. Log onto a computer that has a Win32 console installed using the account AD "Administrator" from the "company.com" domain.
8. Notice how the console security prompts for the username and password. Enter that information and continue.
9. From the console select Tools > Security and notice how that user ("Administrator@") is now listed as a security user even though it was never added directly, but only through AD group membership.

________________________________

Environment


Deployment Solution 6.8 SP2 build 378
Using the Win32 console with security enabled with AD groups imported.

________________________________

Cause


The original express.exe from DS SP2 build 378 was incorrectly caching the NETBIOS domain name in the database. Because the users were cached incorrectly they were not being identified by Active Directory.

________________________________

Resolution


Solution:

1) Backup Express database and express.exe: Backup the database - usually named 'express' - before making any changes. Make a copy of express.exe.

2) Remove improperly cached users: Users who have attempted to login to the Deployment Console with security enabled prior to this fix will have users incorrectly cached in the database. These users must be removed from the securityuser table. To remove these users run the following query against the SQL server:

DELETE FROM securityuser WHERE ad_user = 1 AND user_guid = ''


3) Replace Express.exe: Replace the original express.exe included in SP2 with the express.exe attached to this knowledgebase article.

4) Appy License to Express.exe: Open the license tool under your Deployment Server program files directory. (License.exe) Run the tool to license the express.exe with all applicable licenses.

Note 1: This executable has been through the official Symantec Hotfix process and is supported by Symantec Support Services.

Note 2: No services need to be stopped to affect this change. Only verify that console users have closed any remote sessions to the console. For locally installed consoles, this exe will need to be deployed via DS or NS once licensed.

Note 3: Changes made to express.exe in KB 38727 are also included in the express.exe attached to this KB.

04 December 2007

Carbon Copy Synchronous and Asynchronous Mode Technical Document

Synchronous mode is enabled after the Carbon Copy application is installed , and upon reboot the Carbon Copy remote-control driver (ccvideo4.dll) and a Carbon Copy device interceptor (ccdevice.sys) are installed and placed in the chain between the system video driver and the miniport driver. This driver and interceptor intercepts and evaluates the calls passed for processing. During an actual remote-control session , any changes that occur on the screen of the Carbon Copy clients are emulated back to the Carbon Copy console user on a synchronous line by line basis. So essentially, any object that changes on the client is painted simultaneously line by line in the console user's remote-control window.

Asynchronous mode does not utilize any remote-control driver's but interfaces with the Windows GDI. In this manner, blocks from the actual client's desktop are transmitted back to the console user's remote-control window.(64 x 32 default). This block transmission does not occur concurrently with the changes on the clients desktop so the appearance is a slight delay if you were to have the console and the client machine side-by-side.

28 November 2007

Boot from USB Flash drive

http://www.weethet.nl/english/hardware_bootfromusbstick.php

best practice to enabling WOL proxies using Deployment Server 6.x?

For each broadcast domain that cannot receive Wake-on-LAN (WOL) packets from the Deployment Server, designate one always-on computer to work as the WOL proxy. The WOL proxies must be configured to use TCP/IP to connect to a Deployment Server.In Deployment Server 6.1, one WOL proxy can exist per broadcast domain.
In Deployment Server 6.5, it is possible to enable multiple WOL proxies per broadcast domain because Deployment Server has the ability to dynamically select one WOL proxy per broadcast domain for use.

PXE-E53 error in Deployment Solution 6.8 SP2 with Initial Deploy disabled

In Deployment Solution 6.8 SP2, if Initial Deployment is disabled, the PXE client will display the error "PXE-E53 No boot filename received".

Cause

Prior to Deployment Solution 6.8 SP2, a PXE Client who is not in the Deployment Server's database would get the default PXE boot menu, using the default countdown before booting to the next device. The PXE Server in Deployment Solution 6.8 SP2 is not acting this way; instead, it does not respond to PXE Client requests if the computer is not already in the database when Initial Deploy is disabled.

________________________________

Resolution

To obtain the same reaction of a pre-6.8 SP2 PXE Server, enable Initial Deploy, set the Initial Deploy Boot Option to (None), and the timeout to the desired value.

To do this:

1. Open the Deployment Console.
2. From the Deployment Console open the PXE Configuration Utility (Tools > PXE Configuration).
3. In the PXE Configuration Utility, change to the DS tab.
4. On the DS tab, uncheck Disable Initial Deploy.
5. Change the radio button to the desired timeout option.

26 November 2007

Difference between Domain Browse List and Domain Membership

Domain Browse List and Domain Membership
You can choose to discover all computers currently sharing files or printers running the Messenger service (Domain Browse List), and/or all computers that have trust accounts in the domain (Domain Membership).
The available discovery methods are Domain Browse List and Domain Membership. These settings are used for asynchronous (click Discover Now) and scheduled discovery. Select at least one method.
Domain Browse List
—This option discovers all computers (including Windows 95, 98, 98 SE and ME computers) that are sharing files or printers or are running the Messenger service.
Domain Membership
—This option discovers all computers with trust accounts in the domain. This finds all Windows NT/2000/XP/2003 computers in the domain. However, it will not find any Windows 95, 98, 98 SE and ME computers.
Note: This method is substantially slower than the Domain Browse List method and will not identify the computer’s operating system.
Domain Browse List
The Domain Browse List works by enumerating the records in the computer browse list. This computer browse list was designed for a small, peer-to-peer environment, so it does not scale to large environments well.
When the Notification Server performs a Domain Browse List discovery, it requests a copy of the computer browse list, which includes additional information such as the computer’s operating system and version. It then does a reverse lookup of the computer’s name to get its IP address.
You might have problems discovering computers using this method if:
The computer is not in the computer browse list.
The computer is in the computer browse list but not registered as sharing files.
It can take between 15 and 51 minutes for changes to be reflected in the computer browse list.
Note: The Domain Browse List discovery method gets as much of the computer browse list as it can as fast as it can. This can overload a PDC in a large domain or a multi-domain environment. We recommend you run this outside business hours, preferably over a weekend.
Domain Membership
This works by enumerating the computer accounts in the specified domains.
When you add a Windows NT/2000/XP/2003 computer to a domain, a computer account is created in that domain. This computer account is used by the computer to authenticate with the domain so the computer can authenticate user logons using a secure connection. Windows 9x computers do not create a computer account, which is why you cannot find Windows 9x computers using this method.
When discovering computers using the Domain Membership method, Notification Server catalogs these accounts. Unlike the Domain Browse List method, these accounts have no additional information beyond the computer’s name. Notification Server still does a reverse lookup on the name to get its IP address.
If problems occur using this discovery method, check that accounts exist for these computers using Server Manager (Windows NT 4.0) or Active Directory Users and Computers (Windows 2000 and later).
Both of these methods write errors to the Notification Server log file. If you ever have a problem regarding Resource Discovery, check these log files for information.

Release Notes for Deployment Server 6.9 (Beta)

Windows Server 2008 Support
Deployment Solution 6.9 provides imaging and management support for Windows
Server 2008.
Agent support is provided using DAgent (first introduced on Windows Vista). DAgent
is fully functional on Windows Server 2008 and supports a full range of agent
functionality. DAgent runs on Win32, Win64 and IA64 Itanium platforms.
RDeploy, ImageX, and Ghost Imaging of Windows
Server 2008
Deployment Solution 6.9 provides the ability to capture and deploy Windows Server
2008 images using RDeploy, ImageX, and Ghost using WinPE 2.1. ImageX and Ghost
support Win32 and Win64 platforms in WinPE 2.1.
RDeploy and Image X also provide Windows Server 2008 imaging support on
Itanium platforms, and RDeploy provides support for imaging from Linux automation.
Windows Server 2008 Scripted OS Install Job
Scripted server installations are supported for Windows Server 2008.
WinPE 2.1 Support (see below)
Deployment Solution 6.9 supports WinPE 2.1 for pre-boot and imaging tasks. Older
versions of WinPE are not supported.
Remote Agent install for Deployment Agent
Deployment Solution 6.9 introduces Remote agent install for Vista and Windows
Server 2008.
Support Views based on permission of Group
Deployment Solution 6.9 can restrict viewing of computers from unauthorized users,
based on their rights to manage a given computer. When a user without access
rights to a computer or group of computers logs in, those computers are not visible.
This is option is disabled by default.
VMWare Virtual Center 2.01 support
In the Deployment Console, you can add or import 1.x and 2.x virtual centers. These
virtual centers are displayed in a tree view as Rack and Blade enclosures do with a
visual relationship between the virtual center and the virtual machines that it hosts.
Administrators can visually distinguish a virtual center 1.x from a virtual center 2.x.
Scripted installations of VMWare ESX 3
Deployment Solution 6.9 provides support for scripted installations of VMWare ESX
Red Hat Enterprise Linux 5-update 1 support
Deployment Solution 6.9 supports Redhat Enterprise Server 5 update 1.
Windows CE 6.0 Thin Client support
Deployment Solution 6.9 provides an agent for the Thin Client Windows CE 6.0
operating system. This agent can manage the WinCE 6.0 based Thin Client using the
Deployment Console.
Macintosh OS X 10.5 support
Deployment Solution 6.9 supports OS X 10.5.



Remark :WinPE 2.1 is the only supported version
Deployment Solution 6.9 supports only WinPE 2.1. Since WinPE 2.1 is currently in
beta testing, it is available only to Microsoft beta customers and is not available for
general access.
If you have access to WAIK 2.1 we encourage you to use it. However, due to this
access limitation, this beta version of Deployment Solution supports WAIK 2.0 with
the following limitations:
• WAIK 2.0 does not provide support for Itanium systems.
• Non-RAM boot from CD is not supported. You can still create WinPE 2.0 boot
CDs, but you must select the Boot from RAM option in the Boot Disk Creator
when creating a WinPE 2.0 CD.

14 November 2007

Upgrade RDP (any version)

Before upgrading RDP make sure to unselect Secuirty in Tools-> Security

After the upgrade please select Enable Security again to reactivate security again

It fazils because the AXImport comment used in the scripts does ot have your security account.

08 November 2007

Support for Windows 2008 and Vista SP1

Will Notification Server 7 support Windows 2008?

Will Notification Server 7 support Vista SP1?

Answer


The following information represents current expectations (as of Aug 2007) based upon Microsoft's estimated timelines and Altiris' estimated timelines for NS 7 release.

* NS7 will not initially support Windows 2008 as a host server. Current plan is to add support in a future version of NS7
* NS7 should support management of Windows 2008 (Altiris NS agent)
* NS7 should support management of Vista SP1 (Altiris NS agent)

Note: The last time this article was updated, Microsoft's eta for Windows 2008, and Vista SP1 was Q1 2008

31 October 2007

Error, "Could not start the Altiris Agent service on Local Computer. Error 1067: The Process Terminated Unexpectedly"

Error, "Could not start the Altiris Agent service on Local Computer. Error 1067: The Process Terminated Unexpectedly"


Problem/Symptoms

Altiris Agent is installed on a client computer. Most of the subfolders under C:\Program Files\Altiris\Altiris Agent are created.

The Altiris Agent Service is also installed. However, the Altiris Agent Service starts for few seconds and then stops. If you try to start it manually, the following error appears:

Could not start the Altiris Agent service on Local Computer
Error 1067: The Process Terminated Unexpectedly

Even though I remove and reinstall the Altiris Agent, it doesn't make a difference.

Looking under the Agent log, you can see the following:

"10/25/2007 12:13:50 PM","Client Thread thread 0xCAC beginning"
"10/25/2007 12:13:50 PM","Error reading policy from file C:\Program Files\Altiris\Altiris Agent\Client Policies\ServerName.Domain.com.xml: Error loading policy file: The system cannot find the path specified. (-2147024893). This is normal the first time the agent runs after being installed."
"10/25/2007 12:05:50 PM","Starting version 6.0.2386 on Microsoft Windows Server 2003 5.2 Service Pack 2 Build 3790..."
"10/25/2007 12:05:50 PM","Loading client object: Altiris.AeXClientSessionManager"
"10/25/2007 12:05:50 PM","Loading client object: Altiris.AeXNotificationManager"
"10/25/2007 12:05:50 PM","Loading client object: Altiris.AeXTaskScheduler"
"10/25/2007 12:05:50 PM","Creating CAeXTaskSchedulerThread"
"10/25/2007 12:05:50 PM","Loading client object: Altiris.AeXNetwork.Receiver"
"10/25/2007 12:05:50 PM","Object Altiris.AeXNetwork.Receiver is not installed: Class not registered (-2147221164). This situation should be resolved once the agent rollout has been completed."
"10/25/2007 12:05:50 PM","Loading client object: Altiris.SWD"

The Log will stop suddenly after the above line (Altiris.SWD). New entries will be a repeat of the startup process.

Looking under AeXNSC.log, the following is noticed:

2007-10-25 12:05:43: ==========================
2007-10-25 12:05:43: AeXInstallPreCheck started
2007-10-25 12:05:43: Current dir: C:\DOCUME~1\Admin\LOCALS~1\Temp\apt0
2007-10-25 12:05:43: AeXInstallPreCheck Finished
2007-10-25 12:05:43: ===========================
2007-10-25 12:05:43:
2007-10-25 12:05:43: Passing control to AeXNSAgent
2007-10-25 12:05:43: Commandline: AeXNSAgent.exe ns="ServerName.Domain.com" nsweb="
http://ServerName.Domain.com/ALTIRIS/"
2007-10-25 12:05:43: ===============================
2007-10-25 12:05:43: Core Agent Installation started
2007-10-25 12:05:43: GetInstallPath didnt find installDir in the 6.x key, trying the old key.
2007-10-25 12:05:43: GetInstallPath could not get installDir from the old key, the agent may not be installed.
2007-10-25 12:05:43: Checking minimum requirements.
2007-10-25 12:05:43: Detected NT based Platform.
2007-10-25 12:05:43: RegisterMSXML: MSXML is installed
2007-10-25 12:05:45: Server and web set to ServerName.Domain.com and
http://ServerName.Domain.com/ALTIRIS/
2007-10-25 12:05:45: Product version set to 6.0.0.2386
2007-10-25 12:05:45: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXAgentPages.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXAgentUI.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXBasicInventory.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXSWDAgent.dll has been registered.
2007-10-25 12:05:48: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXTaskSchedulerLib.dll has been registered.
2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AexPackageDelivery.dll has been registered.
2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AeXNetComms.dll has been registered.

2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AtrsMCast.dll has been registered.
2007-10-25 12:05:50: StartAgent, starting core agent.
2007-10-25 12:05:55: StartAgent, starting core agent.
2007-10-25 12:05:55: Core Agent Installation Ended
2007-10-25 12:05:55: ===============================


Environment

Altiris Agent 6.x


Cause

The "Common Files" path wrongly points to a network drive. This is a dangerous practice, as locally installed applications may not have access rights and or permanent access to a network drive. The Altiris Agent (running as Local System) does not have access to the user's network drive (T:) and thus failed when trying to load dependent dlls.

2007-10-25 12:05:45: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXAgentPages.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXAgentUI.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXBasicInventory.dll has been registered.
2007-10-25 12:05:46: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXSWDAgent.dll has been registered.
2007-10-25 12:05:48: RegisterDLL, C:\Program Files\Altiris\Altiris Agent\AeXTaskSchedulerLib.dll has been registered.
2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AexPackageDelivery.dll has been registered.
2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AeXNetComms.dll has been registered.

2007-10-25 12:05:49: RegisterDLL, T:\Program Files\Common Files\Altiris\AtrsMCast.dll has been registered


Resolution

Note: For this article, the mapped drive has the drive letter "T".

  1. Uninstall the Altiris Agent. You can use the following command from the RUN prompt (see article 1995 "Instructions for the complete manual uninstall of the Altiris agent" for more details):

    "C:\Program Files\Altiris\ALTIRIS AGENT\AeXAgentUtil.exe" /clean
  2. Modify the following registry value:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir


    from:

    T:\Program Files\Common Files

    to the default:

    C:\Program Files\Common Files
  3. Reinstall the Altiris Agent.


How to install the Altiris Agent using the Notification Server IP address when the server name cannot be resolved

Question

The Notification Server is installed in a WorkGroup or Domain where computers in other Sites or Domains are only able to resolve the IP address of the Notification Server and not the Server Name. How can the Altiris Agent be pushed using the IP address of the Notification Server only?


Answer

You need to add some switches for the AexSWDInstSvc (Altiris Agent Installation Service) program.

  1. Under Altiris Agent Installation page (under Configuration > Altiris Agent > Altiris Agent Rollout), open the Installation Settings page.
  2. Under Specify Different Notification Server, add the IP address of your Notification Server (to look something like this: http://10.103.65.109)
  3. Under Additional Parameters add the following switches:
    • -u
    • -s
    • -w

(to look like this: -u http://10.103.65.109/Altiris/NS/NSCap/Bin/Win32/X86/NS Client Package/AeXNSC.exe -s 10.103.65.109 -w http://10.103.65.109/Altiris/).

  1. Then push the Altiris Agent.

For more details about AeXSWDInstSvc commands, see article 38380, "AeXSWDInstSvc (Altiris Agent Installation Service) Command Line Arguments."

See article
29334, "How to manage computers from different domains (without trust relationship between domains) from a single Notification Server" for more references about computers in multiple domains.

26 October 2007

Configuring Application Metering to use the "Installed vs. Used" report

Question
How do I configure Application Metering to collect the data necessary for the "Installed vs. Used" report?

Answer
The "Installed vs. Used" report is dependant on both Application Metering and Inventory solution to collect the required data. Use the steps below as a guideline when configuring Notification Server for this report:

1. Install Altiris Application Metering Solution 6.1.
2. Install Altiris Inventory Solution 6.1.
3. Configure Inventory Solution Solution:

* Navigate to the Tasks tab > Assets and Inventory > Inventory > Windows > Inventory Tasks.
* Select Software Inventory.
* Enable the task and then click Apply. Software inventory needs to have executed and reported back to the Notification Server.

This step generates the install counts.

4. Configure the Application Metering Solution with the proper settings:

* Navigate to the Configuration tab > Solution Settings > Software Management > Application Metering.
* Select Application Metering Solution Configuration.
* Verify that "Clients Send Summary Data every: XXXX" is enabled and choose an appropriate time interval for your environment. (The lower number clients means shorter amount of time you can set this without negatively impacting the network.)
* Determine which Inventory Solution Integration setting is necessary for your environment. "Client based Inventory Solution" setting is most commonly used.
* Click Apply.

5. Configure and enable a Monitor Policy for each application you need to track:

* Browse to Tasks > Software Management > Application Metering > Application Monitors.
* Right-click Application Monitors and select New > Application Monitor Policy.
* Edit the Name and Description fields.
* Click Add Application Definition to specify the monitored application

* Define the monitor policy based on "Internal Name" alone, if possible. This provides reliable results when monitoring applications.
* Start/Stop/Denial events are not required to be enabled for the "Installed vs. Used" report to work.

Steps 4 and 5 generate the used counts.

6. If the Application Metering Agent is not installed, deploy it to the proper collection of client computers in the environment. Make sure the clients in this collection also overlap with clients from Step 3.
7. Update the client computer's configuration, or allow the scheduled update configuration interval to lapse.

After the above process is complete, the client computers should have both the Application Metering sub-agent and the Inventory Agent Package present in the Altiris Agent Details window.
________________________________


Follow-up information based on the above process:

* The Month Year drop down will populate once client summary data has been processed by the Notification Server.
* The default report will return run counts from user who are logged into a domain. For a modified report that will also return run counts from users logged in locally, see related article 35341 <https://kb.altiris.com/articleRedirect.asp?aid=35341> .

Note: These steps outline how to retrieve Application Usage data using the default settings of both Inventory Solution and Application Metering solution. You may need to configure the tasks above specifically for your environment.

25 October 2007

What is AltirisNSCabInstaller.exe?

Question
What is the purpose of the AltirisNSCabInstaller.exe file found in C:\Program Files\Altiris\Notification Server\nscap\bin\win32\x86\NS CAB Installer Package?

Answer
AltirisNSCabInstaller.exe is installed in C:\Program Files\Altiris\Notification Server\nscap\bin\win32\x86\NS CAB Installer Package. The .EXE contains all of the ActiveX controls required to run the console, and is designed to be distributed to locked down computers. Best practice would be to create a collection of Administrators computers or anyone who would access the console (especially helpdesk) and push the .EXE to them via SWD. You could also make this available via URL or Software Portal.

24 October 2007

Software delivery and Data Purging

For those who uses the status event on Software delivery for reporting purposes be aware that the default purging is set to 7 days. Meaning that is a deployment of software oversapns more than a week your reporting information will NOT be correct due to purging.

So, if you want to use the Software delivery status reports change the default data purging settings on the Software Delivery configuration tab to more the 7 days

23 October 2007

Retired computers don't automatically change back to active

Problem/Symptoms

Retired computers do not become active again after sending Inventory to the Notification Server. This causes problems for scenarios in which the server is automatically retiring computers that have not reported inventory in a specified time period (specified under Purging Maintenance) while some of the computers are still managed computers that have been offline for the specified time period.

Cause

The cause of the problem is that the Notification Server discards almost all event data from retired computers. It was not designed to reactivate retired computers when inventory is received but instead discards the inventory event. On a retired computer, when opening up the client UI, go to About > Altiris Agent Details, and click the Send Basic Inventory button. Notice that the Basic Inventory Last Sent time will never change. This is because the client never received any acknowledgement from the server that the inventory was received (because it was discarded).

Resolution

The only events sent by the Altiris Agent that are received by the server are the AeX Client LogOn events. These are sent to the server whenever a user logs on or off the computer.

To aid in identifying these computers download the report that will show retired computers that have sent event data for the specified data class (default to AeX Client LogOn) within the last n time units (for example, 30 days, 45 minutes, 6 hours, etc.). Select multiple computers from the report results, right-click on them and change their status back to Active.

This process can be automated by creating a Notification Policy. See article
16909. You can use the query shown below. It reports any retired computer that has sent a client logon event in the past 24 hours.


select distinct _resourceguid from evt_aex_client_logon ac  

join resourceassociation ra on ac._resourceguid = ra.parentresourceguid

where ra.resourceassociationtypeguid like '%3028166f%'

and ra.childresourceguid like '%492c463b%'

and datediff(hh, ac._eventtime, getdate())< 24

NS Agent - nominated Package Server maximum download retry time

Question

How long will the Altiris Agent continue to try to download from a nominated Package Server before bypassing the site maintenance settings (Package Server) and download directly from the Notification Server?

Answer

This is really a question about Notification Server site maintenance behavior rather than Agent behavior. See KB2397 for more information on site maintenance. The Altiris Agent always downloads from the codebases that are given out by the Notification Server.

New in Notification Server 6.0 SP2 is that the NS no longer hands out its own codebases to agents that are members of a site; this change was due to a very common customer request. To compensate for this change in behavior a new CoreSettings.config item was created and is disabled by default (meaning agents will strictly adhere to the site maintenance configuration):

MaxAgentDownloadTryingTimeMins

The agent now will send a running time value to the server when it makes its calls to GetPackageInfo.aspx on the Notification Server. When this time value exceeds the MaxAgentDownloadTryingTimeMins value the NS will hand out its own codebases in place of the codebases of any Package Server within the given site. Please note that this is a global setting, and cannot be configured for indiviual sites.

The preferred method to implement MaxAgentDownloadTryingTimeMins on the Notification Server is to use the NSConfigurator. The NS 6.0 SP3 release notes, section 3.1.25, provides information on how to install and use the NSConfigurator (KB19106).

Manually installing the Altiris Diagnostics Pack

Question

Where can I manually download the latest public version of the Altiris Diagnostics pack?


Answer

As of 1 November 2006, the most recent public version of the Altiris Diagnostics Pack was 6.1.7631.

The diagnostic pack includes the following:

  • Altiris Log Viewer
    • This utility can be used remotely from the NS to review NS log files, but won't be able to resolve GUIDs to object names.
  • Altiris Profiler
  • NS Diagnostic tool (NSDiag.exe)
  • Import Export Utility
  • The set application identity utility (setid.exe)
  • NScript runner
  • NS Configurator installation file (NSConfigurator.msi)

Some customers may have firewalls that block access to the self-update functionality. It may also be beneficial to install the diagnostics pack on administrators computers and as part of an upgrade readiness health check on pre–Notification Server 6.0 SP3 servers (diagnostics pack was included with SP3).

If you are going to install the diagnostic tools, make sure the Microsoft .Net 1.1 is installed on the computer or some of the diagnostics tools, specifically the Logviewer (logviewer.exe) will not work. When the diagnostic tools are installed they are located (by default) at C:\Program Files\Altiris\Diagnostics. You may want to create a shortcut to the logviewere.exe and place it on your desktop for easy access.