SCOM Infrastructure Recap Ing. Ondřej Ševeček GOPAS a.s. MCM:Directory MVP:Enterprise Security CEH:Certified Ethical Hacker CHFI: Computer Hacking Forensic Investigator CISA ondrej@sevecek.com www.sevecek.com GOPAS: info@gopas,cz www.gopas.cz www.facebook.com/p.s.gopas SCOM management server Microsoft Monitoring Agent works as agent on the MS TCP 5723 listening for client communications performs modules running on MS several s of MonitoringHost.exe for running anything System Center Data Access Server TCP 5724 listening for console/powershell/msagent communication accesses databases directly System Center Management Configuration performs some MS management functions against database directly accesses databases directly 1
SCOM management server and PowerShell Get-SCOMManagementServer SCOM agent Microsoft Monitoring Agent HealthService Operations Manager event log 1210 - new configuration became active 1201 - new MP downloaded TCP 5723 to MS agent permanent TCP connection heartbeat every several seconds notifications from MS agent about new configuration irrespective of heartbeat Agent proxy can create hosted objects on other computers 2
SCOM management agent and PowerShell Get-SCOMAgent Management pack XML configuration plus scripts.xml,.mp file or.mpb bundle file Sealed (digitally signed) or un-sealed and modifiable different MP cannot target/reference objects from an unsealed MP cannot define classes Strict versioning can update any management pack with newer version dependent MPs should work cannot remove MP which other MPs depend on Downloaded to clients %programfiles%\microsoft Monitoring Agent\Agent\Health Service State\Management Packs 3
Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very 4
Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very Sevecek.Overrides Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very 5
Better to separate overriding MPs Sevecek.Overrides AD Microsoft.Windows.Server.AD.2008.Monitoring Active Directory Server 2008 and above Monitoring Sevecek.Overrides DNS Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very Management pack elements base/abstract class inherited object object singleton rule rule 6
Concept of targeting Agent object object class rule rule @IsRODC ReadOnlyDC.Computer DFSR Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very Domain Forest Site SiteLink DomainControllerRole 7
@IsRODC ReadOnlyDC.Computer Microsoft.Windows.Server. AD.2008.Monitoring Active Directory Server 2008 and above Monitoring DFSR Microsoft.Windows.Server.AD.2000.very Active Directory Server 2000 very Domain Forest Site SiteLink DomainControllerRole 8