Is it possible to update check-allow-list by creating check definition.

Hank Woo
Tera Guru

Hi All,

 

I am continuously developing discovery pattern at customer request and discovering with acc-v.
As the pattern is developed, the check-allow-list should also be updated, which is too cumbersome.
If you can create a check definition, can you make a check that updates the check-allow-list?
Has anyone tried it?

1 ACCEPTED SOLUTION

James Behrens
Giga Guru

If I am reading this correctly, it looks like you want to be able to update the contents of the check-allow-list on the deployed agents from the instance. If that is what you are asking, then the answer should be no. 

Go on a client and look at the permissions on the folders and files in c:\programdata for agent client collector. The check-allow-list file defaults to the two initial checks and the service account is only granted read rights from there. Picture it as the server owner's last stand to control what checks can be run by ServiceNow.

 

Please call me out if that is not correct. I'm pretty sure that is the case though. 

View solution in original post

1 REPLY 1

James Behrens
Giga Guru

If I am reading this correctly, it looks like you want to be able to update the contents of the check-allow-list on the deployed agents from the instance. If that is what you are asking, then the answer should be no. 

Go on a client and look at the permissions on the folders and files in c:\programdata for agent client collector. The check-allow-list file defaults to the two initial checks and the service account is only granted read rights from there. Picture it as the server owner's last stand to control what checks can be run by ServiceNow.

 

Please call me out if that is not correct. I'm pretty sure that is the case though.