User Guide

How to prepare discovered devices for audit

Remote troubleshooting for discovered devices is available from a segment's Scan Results. Use Troubleshoot to diagnose and prepare one device, or use Bulk Troubleshoot to set audit credentials or enable PowerShell remoting for multiple devices.

Troubleshoot one device

  1. Open Network > Segments, then open the segment that contains the device.
  2. In Scan Results, hover over the device's status in the Ready for audit column.
  3. Click the wrench next to the status. You do not need to select the row first.
  4. In the Troubleshoot dialog, read the checks from top to bottom. If a check has Failed, start with the first failed check.

The dialog can show these results:

  • Passed — the check completed successfully.
  • Failed — the check found a prerequisite that you need to resolve.
  • Skipped — an earlier failure prevented the check from running, or the check does not apply to the current audit path.
  • Found / Not found — the Audit Agent result. Found means that AlloyScan can use the agent-based audit path; agentless checks may show Skipped, and Audit Service credentials are not required. Not found is neutral and does not block the agentless audit path. To use an Audit Agent instead, see Use an Audit Agent as an alternative.

NOTE: The checks and actions depend on the device type shown in the dialog. Do not infer the type from the device name.

Change the device type

Use Change when AlloyScan detected the wrong device type or shows Unknown device and you know the correct type.

  1. Next to Device type, click Change.
  2. In Set device type for device, select the correct Device type.
  3. Click Save.
  4. In the Troubleshoot dialog, click Recheck.

Set credentials

Use Set credentials to choose a compatible saved credential for the agentless audit path.

  1. Click Set credentials.
  2. Select a compatible credential, or select Segment defaults to use the segment's default credential.
  3. Click Save.
  4. In the Troubleshoot dialog, click Recheck.

Investigate a connection failure

  1. Next to the failed connection check, click View log.
  2. Use the log details to identify and resolve the cause of the connection failure.
  3. Return to the Troubleshoot dialog and click Recheck.

    Recheck reruns the applicable prerequisite checks and updates Ready for audit. It does not run an audit.

For a single Windows device, enable PowerShell Remoting using standard Windows administration tools, then click Recheck. To enable it remotely for multiple Windows devices, use Bulk Troubleshoot.

For Linux and macOS agentless audit, make sure SSH is running on the target and accessible from the Audit Service on TCP port 22 by default.

Troubleshoot multiple devices

Bulk Troubleshoot supports two operations:

  • Set audit credentials for a selection containing supported device types.
  • Enable PowerShell remoting when every selected device is a Windows device.

Before you begin

  • Make sure the Audit Service assigned to the segment is online.
  • For credential assignment, make sure compatible saved credentials are available for every device type in the selection.

Open Bulk Troubleshoot

  1. In the segment's Scan Results, select at least two devices.
  2. On the action toolbar, click the wrench.

The Bulk Troubleshoot Operation dialog shows the number of selected devices and the operations available for the selection.

Set audit credentials

  1. Select Set audit credentials.
  2. For each device-type group, select a compatible saved set of credentials.
  3. Click Start Operation.

    Start Operation remains unavailable until every device-type group has a credential selection. Successfully processed devices receive the selected credentials.

Enable PowerShell remoting

  1. Make sure every selected device is a Windows device.
  2. Select Enable PowerShell remoting.
  3. Click Start Operation.

If the operation is not available, remove non-Windows devices from the selection.

Monitor the operation

  1. While the operation runs, review the number of processed devices and the Successful and Failed totals.

    Successful only means that the selected bulk operation completed successfully for the device. It does not guarantee that the device is Ready for audit.

  2. To investigate a device result, click View log. Use Filter or Search to find an entry, or click Download TXT to save the log.

  3. To stop an operation that is still running, click Cancel Operation. Changes already completed on processed devices are preserved; devices that have not been processed remain unchanged.

If a device remains Not Ready for audit, open its individual Troubleshoot dialog and resolve the remaining failed prerequisites.

Use an Audit Agent as an alternative

An Audit Agent is an alternative way to audit a Windows, Linux, or macOS computer when you do not want to or cannot configure agentless access.

  • Install is available when AlloyScan does not find an Audit Agent on the computer.
  • Reinstall is available when an Audit Agent is associated with another Site. Reinstalling unlinks the agent from the previous Site and sends future audit data to the current Site.

For the complete remote installation procedure and manual installation options, see How to install Audit Agents.

Verify readiness

Return to Scan Results and confirm that the device is marked Ready for audit. If you changed an individual prerequisite and the status has not refreshed, open Troubleshoot and click Recheck.

When the device is ready, see How to audit devices.