跳至內容

Patch Manager: Patch compliance vs Association compliance

0

I'm trying to set up patch manager to automatically scan for updates to dependencies of my EC2 instances running AL2023.

I've followed this guide to set up patch manager to run scans.

Scans are running based on the schedule and I am able to manually trigger the association but this doesn't report any non-compliance.

However when I use the console and run, patch now, in patch manager this reports as non-compliant in systems manager compliance section.

From my understanding both my association and patch now are running AWS-RunPatchBaseline command.

This doesn't make sense to me why they have different results but are running the same thing. I have removed the patch base line from the association and think I am relying on the default base line for AL2023.

Looking in the Systems Manager > Fleet Manager > Managed nodes > {instance} > Configuration compliance and filtering on compliance type. There are only three items for association which don't have names but execution times match the last time I ran the association.

Does anyone have any ideas? Thanks

已提問 1 年前檢視次數 431 次
1 個回答
0

Hi, That should be working as you expect - do you definitely have the associations to all the instances set correctly? Have you looked into the output of the job - maybe it is for some reason reporting success when actually the scan part did not run?

Cheers, Rich

AWS
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。