comunic 4 Posted February 10, 2016 Posted February 10, 2016 Hi, here is my question : Is there a way to prepare an agent to be installed on computers, and join a specific static group. The goal is to make one personnalized installer for each site or client, and when we use it, the machine is automatically classified to a predefined static group. Thank's !
21jags 0 Posted February 11, 2016 Posted February 11, 2016 You can create new static group on your own and shifts the client systems as per your requirement. The pre-defined static group takes the data from dynamic group. You need to make changes in dynamic groups as per your requirement. Follow the link to create new dynamic group. hxxp://support.eset.com/kb3741/.
comunic 4 Posted February 11, 2016 Author Posted February 11, 2016 (edited) Hi 21jags, it's ok for to manage dynamic groups, but nothing on it (like a specific marker) make possible for newly installed agent to join them automatically. We could insert a marker in the agent installer, and make it recongized by a dynamic group. for example, if i installed agents on remotes and branch office, nothing make me able to reconized which computer is on which place with dynamic groups. Edited February 11, 2016 by comunic
mahiralkhoir 4 Posted February 11, 2016 Posted February 11, 2016 Nope, i am trying to find that way. The only way you can assign static group when install agent is using agent server assistant installation.
comunic 4 Posted February 11, 2016 Author Posted February 11, 2016 you can detail me that procedure ?
ESET Staff MichalJ 434 Posted February 11, 2016 ESET Staff Posted February 11, 2016 Server assisted installation requires manually executing the installer on a machine, and machine has to have visibility to ERA Server. You need to ship the webconsole credentials during this procedures, as this will basically create a new computer in the server, so you need to be authorized for such action. Possible workaround is to take advantage of certificates and dynamic groups. You create separate certificates for every branch office, and then create dynamic groups every one branch office (dynamic group template, with condition based on the used certificate). This won´t place the agent into the static group however, you will need to do it manually from time to time. But should help with the identification of machines. We are working on improving this process for the future versions of ERA 6.
comunic 4 Posted February 11, 2016 Author Posted February 11, 2016 I try to create a certificate, and assign it to the live installer, this is ok. But which certificate item do i have to check on the dynamic filter group ? Subject ? Serial Number ? Issuer ? thanks
ESET Staff MartinK 384 Posted February 11, 2016 ESET Staff Posted February 11, 2016 I try to create a certificate, and assign it to the live installer, this is ok. But which certificate item do i have to check on the dynamic filter group ? Subject ? Serial Number ? Issuer ? thanks Use serial number as that is only one field to be unique - all others can be the same ...
comunic 4 Posted February 12, 2016 Author Posted February 12, 2016 ok this is done, the eset live installer is generated with a created certificate, but at the end of the agent installer, it makes a rolling back and doesnt install !
comunic 4 Posted February 14, 2016 Author Posted February 14, 2016 (edited) ok this is working. anyways, do you know if there is a way to put a static group as a parameter for the agent live installer ? Edited February 14, 2016 by comunic
ESET Staff MichalJ 434 Posted February 15, 2016 ESET Staff Posted February 15, 2016 No, as of now this is not possible. We are however tracking improvement to allow this in the future releases of ERA 6.
comunic 4 Posted March 5, 2016 Author Posted March 5, 2016 (edited) hi again, i choose to deploy every clients with specific certificate (in relation with a dynamic group based on the cert ID). The computers appears on the good dynamic group on the contrary, the problem is that i can't find in a computer details witch dynamic group does it belong to ? we can see the parent static gorup and that'all Edited March 5, 2016 by comunic
ESET Staff MichalJ 434 Posted March 7, 2016 ESET Staff Posted March 7, 2016 (edited) Hello, it is not possible in the way you want to have it done as of now. You can however check the created dynamic group in "computers" section or "admin/groups", for the members that are in the group. For your use-case, we will track a requirement, however, I would like to know the use-case, you would like to cover? What you would do, after you see this information in computer details? You would manually put it in a different static group, or? Edited March 7, 2016 by MichalJ
comunic 4 Posted March 7, 2016 Author Posted March 7, 2016 hi, yes i will do it that way : i need to send to my client or technician a script related to one and only one client (i can't take the risk to have a new "unknown computer" and we can't see the public ip in the console, and we can't insert a static group in the live installer) so i will create a unique certificate for each client, in relation with a dynamic group.all the dynamic groups will have the lost and found as parent group. now if a have hundreds of dynamic groups, i need to know easily if a new computer appear, what client is it. so i will now have to check all the dynamic groups.. all of this to finally put the good client in the good static group, with the good policies, tasks, licences...
Recommended Posts