User Guide

Prepare discovered devices for audit

Use the troubleshooting actions in a segment's Scan Results to understand why a discovered device is not ready for audit and fix the issues preventing it from being audited. You can troubleshoot one device or use Bulk Troubleshoot to set audit credentials or enable PowerShell remoting for multiple devices.

Troubleshoot one device

  1. Open Network > Segments, then open the segment that contains the device.
  2. In Scan Results, hover over the device's status in the Ready for audit column.
  3. Click the wrench next to the status. You do not need to select the row first.
  4. In the Troubleshoot dialog, read the checks from top to bottom. If a check has Failed, start with the first failed check.

The dialog can show these results:

  • Passed — the check completed successfully.
  • Failed — the check found a prerequisite that you need to resolve.
  • Skipped — an earlier failure prevented the check from running, or the check does not apply to the current audit path.
  • Found — AlloyScan found a working Audit Agent associated with the current Site.

    When Audit agent shows Found, the device can use the agent-based audit path. The Device type, Test connection, Trusted connection, Credentials, and PowerShell remoting checks can therefore show Skipped. This is expected and does not indicate a problem. Audit Service credentials are not required for this path.

  • Not found — no Audit Agent was found on a computer.

NOTE: The checks and actions depend on the device type shown in the dialog. Do not infer the type from the device name.

For agentless Windows audit, the target computer must be in the same domain as the Audit Service computer. Use an Audit Agent to audit a Windows computer in another domain.

Change the device type

Use Change when AlloyScan detected the wrong device type or shows Unknown device and you know the correct type.

  1. Next to Device type, click Change.
  2. In Set device type for device, select the correct Device type.
  3. Click Save.
  4. In the Troubleshoot dialog, click Recheck.

Set credentials

Use Set credentials to choose a compatible saved credential for the agentless audit path.

  1. Click Set credentials.
  2. Select a compatible credential, or select Segment defaults to use the segment's default credential.
  3. Click Save.
  4. In the Troubleshoot dialog, click Recheck.

NOTE: A working Audit Agent does not use Audit Service credentials.

Investigate a connection failure

  1. Next to the failed connection check, click View log.
  2. Use the log details to identify and resolve the credential or connectivity problem.
  3. Return to the Troubleshoot dialog and click Recheck.

    Recheck reruns the applicable prerequisite checks and updates Ready for audit. It does not run an audit.

For Linux and macOS agentless audit, the Audit Service connects to the target through SSH on TCP port 22 by default, and the SSH server must be running on the target. This SSH requirement does not apply when a working Audit Agent provides the audit data.

Troubleshoot multiple devices

Bulk Troubleshoot supports two operations:

  • Set audit credentials for a selection containing supported device types.
  • Enable PowerShell remoting when every selected device is a Windows device.

Before you begin

  • Use a segment with an online Audit Service.
  • Select at least two discovered devices. Devices can be ready or not ready for audit.
  • For credential assignment, make sure the Audit Service has a compatible saved credential for every device type in the selection.

Open Bulk Troubleshoot

  1. In the segment's Scan Results, select at least two devices.
  2. On the action toolbar, click the wrench.

The Bulk Troubleshoot Operation dialog shows the number of selected devices and the operations available for the selection.

Set audit credentials

  1. Select Set audit credentials.
  2. For each device-type group, select a compatible saved credential.
  3. Click Start Operation.

    Start Operation remains unavailable until every device-type group has a credential. Successfully processed devices receive the selected audit credentials.

Enable PowerShell remoting

  1. Make sure every selected device is a Windows device.
  2. Select Enable PowerShell remoting.
  3. Click Start Operation.

If the operation is not available, remove non-Windows devices from the selection.

Monitor the operation

  1. While the operation runs, review the number of processed devices and the Successful and Failed totals.

    Successful only means that the selected bulk operation completed successfully for the device. It does not guarantee that the device is Ready for audit.

  2. To investigate a device result, click View log. Use Filter or Search to find an entry, or click Download TXT to save the log.

  3. To stop an operation that is still running, click Cancel Operation. Changes already completed on processed devices are preserved; devices that have not been processed remain unchanged.

If the device remains Not Ready for audit, open its individual Troubleshoot dialog and resolve the remaining failed prerequisites.

Verify readiness

Return to Scan Results and confirm that the device is marked Ready for audit. If you changed an individual prerequisite and the status has not refreshed, open Troubleshoot and click Recheck.

When the device is ready, see How to audit devices.

Use an Audit Agent as an alternative

An Audit Agent is an alternative way to audit a Windows, Linux, or macOS computer when you do not want to or cannot configure agentless access.

  • Install is available when AlloyScan does not find an Audit Agent on the computer. Audit agent: Not found is a neutral result and does not prevent you from preparing the computer for an agentless audit.
  • Reinstall is available when an Audit Agent is associated with another Site. Reinstalling unlinks the agent from the previous Site and sends future audit data to the current Site.

For the complete remote installation procedure and manual installation options, see How to install Audit Agents.