: HIP Objects Patch Management Tab
Focus
Focus

HIP Objects Patch Management Tab

Table of Contents

HIP Objects Patch Management Tab

  • ObjectsGlobalProtectHIP Objects<hip-object>Patch Management
Select the Patch Management tab to enable HIP matching on the patch status of the GlobalProtect endpoints.
HIP Object Patch Management Settings
Description
Patch Management
Select this option to enable matching on the patch management status of the host and enable the Criteria and Vendor tabs.
Criteria tab
Specify the following settings:
  • Is Installed—Match on whether patch management software is installed on the host.
  • Is Enabled—Match on whether patch management software is enabled on the host. If the Is Installed selection is cleared, this field is automatically set to none and is disabled for editing.
  • Severity—Select from the list of logical operators for matching on whether the host has missing patches of the specified severity value.
    Use the following mappings between the GlobalProtect severity values and the OPSWAT severity ratings to understand what each value means:
    • 0—Low
    • 1—Moderate
    • 2—Important
    • 3—Critical
  • Check—Match on whether the endpoint has missing patches.
  • Patches—Match on whether the host has specific patches. Click Add and enter the KB article IDs for the specific patches to check for. For example, enter 3128031 to check for the Update for Microsoft Office 2010 (KB3128031) 32-Bit Edition.
Vendor tab
Define specific vendors of patch management software and products to look for on the endpoint to determine a match. Click Add and then choose a Vendor from the drop-down. Optionally, click Add to choose a specific Product. Click OK to save the settings.