내용으로 건너뛰기

Patch Manager: Patch compliance vs Association compliance

0

I'm trying to set up patch manager to automatically scan for updates to dependencies of my EC2 instances running AL2023.

I've followed this guide to set up patch manager to run scans.

Scans are running based on the schedule and I am able to manually trigger the association but this doesn't report any non-compliance.

However when I use the console and run, patch now, in patch manager this reports as non-compliant in systems manager compliance section.

From my understanding both my association and patch now are running AWS-RunPatchBaseline command.

This doesn't make sense to me why they have different results but are running the same thing. I have removed the patch base line from the association and think I am relying on the default base line for AL2023.

Looking in the Systems Manager > Fleet Manager > Managed nodes > {instance} > Configuration compliance and filtering on compliance type. There are only three items for association which don't have names but execution times match the last time I ran the association.

Does anyone have any ideas? Thanks

1개 답변
0

Hi, That should be working as you expect - do you definitely have the associations to all the instances set correctly? Have you looked into the output of the job - maybe it is for some reason reporting success when actually the scan part did not run?

Cheers, Rich

AWS
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.