Quest InTrust Connector for MOM - Readme

This file contains last-minute product information and updates to the documentation.

Contents

Welcome to Quest InTrust Connector for MOM
System Requirements
Installation
Known Issues

Welcome to Quest InTrust Connector for MOM

Quest InTrust Connector for Microsoft Operations Manager is a tool that helps to establish a single, comprehensive workflow for managing your Windows-based network. Using this tool, you can integrate the InTrust capabilities of tracking the business-critical security events into the existing enterprise-wide system of network operations management. In particular, InTrust Connector for MOM package includes:

To learn more about Quest InTrust Connector for MOM, please refer to the User’s Guide.

System Requirements

Required Permissions

The account under which InTrust Connector for MOM service will run (service account) must be granted the following access rights:

During the InTrust Connector for MOM setup, the InTrust Connector Administrators group is created, containing user account used to run the setup. The InTrust Connector for MOM service account is also added to this group. The InTrust Connector Administrators group members are assigned the rights and permissions described below.

Note that the InTrust Connector Administrators group is not removed upon uninstalling of InTrust Connector for MOM. You need to remove it manually.

  1. For the ITConMOM.xml file in the InTrust Connector for MOM working folder:
  2. For the HKEY_LOCAL_MACHINE\SOFTWARE\Quest Software\InTrust Connector for MOM registry key:
  3. For the InTrust Connector for MOM service:

Note: When granting the necessary permissions manually, clear the Allow inheritable permissions from parents to propagate to this object check box.

The following accounts should be added to the InTrust Connector Administrators group as necessary:

The user account that will be used to uninstall Quest InTrust Connector for MOM must be included into the local group on the computer where the MOM Server runs:

Installation

The Quest InTrust Connector for MOM installation package contains the following components:

To install InTrust Connector for MOM to the computer that meets system requirements, run the InTrustConnector.msi.

To use InTrust Management Pack for MOM, browse for the target location you need, and copy the InTrustManagementPack.akm file to that location.

To learn about Quest InTrust Connector for MOM, open the User Guide.


Known Issues

B109722 For alerts forwarded to MOM 2000 database from the InTrust Alert database, the values of TimeOfFirstEvent and TimeOfLastEvent fields are generated incorrectly because of the way MOM 2000 fills these data fields in its alerts.
B110226 For computers in Maintenance Mode, MOM 2005 automatically changes states of all alerts to Resolved.
MOM makes these updates in a way that doesn’t allow InTrust Connector pick the changes and send them back to InTrust, even if the Forward alerts. Synchronize alert states back to InTrust option is selected. Therefore, these updates are not visible in InTrust.
B110219 When changes are made in MOM to any field of an alert other than Alert state or Comment, MOM displays a comment on the change in its user interface but doesn't save it to the alert history in the database. Therefore InTrust Connector cannot synchronize the comment to that update with the InTrust database and the comment does not appear in the InTrust alert properties when synchronized.
B110196 When an alert is updated in MOM 2000, and alert state is synchronized back to InTrust (Forward alerts. Synchronize alert states back to InTrust mode), MOM 2000 generates a comment about forwarding the change in alert state to InTrust and writes it to the alert history in its database. However, MOM 2000 does not return this comment to InTrust Connector and therefore an extra alert update with an empty comment appears in InTrust.
B109843 When InTrust Connector that used to work with some specific MOM server is reconfigured to now work with another, and the InTrust Connector service is unable to access the “old” MOM server when restarting to pick up this configuration change, InTrust Connector may be unable to switch back to that MOM server again later.
You will get the following error in InTrust Connector while trying to connect to the MOM server:

"Cannot start connector. 0xaadc0004 MOM Connector Framework error. The specified ForwardeeName is in use already!"

To make it possible for InTrust Connector to use that MOM server again, you will have to manually unregister the InTrust Connector there. To do that, run the following SQL batch on the MOM OnePoint database:

DELETE MCF_RegisteredDataChanges FROM MCF_RegisteredDataChanges INNER JOIN MCF_Forwardees ON MCF_Forwardees.ForwardeeId = MCF_RegisteredDataChanges.ForwardeeId WHERE MCF_Forwardees.ForwardeeName like N'Quest InTrust Connector%'
GO
DELETE FROM MCF_Forwardees WHERE ForwardeeName like N'Quest InTrust Connector%'”
GO

B109046 To protect the account passwords stored in the registry, you need to apply security settings to the registry entry. See Quest InTrust Connector for MOM User Guide for details on the minimum access rights to the registry required for the InTrust Connector operation.
B110495 You may get the following error while trying to reinstall InTrust Connector:

"Cannot create service: 0x000003E5. Restart your computer and run setup again."

Check if the Services snap-in is open on the computer where you are reinstalling InTrust Collector. Close is the snap-in, and try to install InTrust Connector again.
B110169 If InTrust Server and MOM Server are located in different time zones, timestamps of alert updates in InTrust Monitoring Console will display, for alerts synchronized from MOM to InTrust, local time of those updates on the MOM server and not on the InTrust Server computer. Consider the time difference between servers when reviewing alert update history with InTrust Monitoring Console.
B110694 The following errors may occur when alerts are resolved with MOM 2000:

Failed to retrieve processing rule’s comment.
The object you are attempting to delete is referenced by another object. To delete the object, first delete all references to it
Error 0x00040ed2: Unknown error code 265638.
Error 0x80040e2f,.SQL:3621, 01000.
Error 0x80040e2f,.SQL:547, 23000.

Failed to update alert.
Another version of this object was saved while you were editing.
Please refresh the data and make your changes again.
Unknown error 0x40ED2.
Error 0x00040ed2: Unknown error code 265638.

To resolve the situation, refresh the alerts view.
B110674 If MOM Server or MOM Connector Framework Web Service is not found at the URL to which InTrust Connector for MOM tries to connect, the following error is displayed:

"Error:Connector:Host not found. HRESULT=0x800A1521 - Connector:Unspecified HTTP error. HRESULT=0x800A1518"

For detailed information, see Error Details.
B111060 If you try to select the account used to connect to the InTrust Alert database from a different domain using the Browse button, and the account under which the InTrust Connector for MOM Configuration Wizard is run has insufficient rights to browse accounts in that domain, Configuration Wizard may crash with a Dr.Watson error.
B109743 Alerts suppressed in InTrust according to InTrust rules settings, are not forwarded to MOM
B110339 If you reconfigure InTrust Connector to work with a different MOM server that does not have InTrust Management Pack installed, that MOM server may log the following error: "Data Access Error...Invalid type or value Parameter name: RuleId... ." Restart the World Wide Web Publishing service on the MOM server to resolve this problem.
B110655 On a heavy loaded MOM server that also has automatic resolution enabled for alerts (as a part of its Database Grooming settings) InTrust Connector in the Forward alerts. Synchronize alert states back to InTrust mode may be unable to synchronize alert states from MOM to InTrust. This happens because MOM Server returns an error to InTrust Connector that requests alert state changes.



Disclaimer

The information in this publication is furnished for information use only, does not constitute a commitment from Quest Software Inc. of any features or functions discussed and is subject to change without notice. Quest Software, Inc. assumes no responsibility or liability for any errors or inaccuracies that may appear in this publication.

Last revised November 5, 2004

Copyright © 2004 Quest Software, Inc. and Quest are registered trademarks of Quest Software.