Patch installation, distribution, and monitoring
Before you begin an upgrade, it is helpful to familiarize yourself with how to upload and install patches, monitor patch installations, and verify that installations are successful.
Install a patch using scp
When upgrading your Guardium environment, there are several ways to upload and install patches on central managers and managed units.
- Perform or schedule the patch installation during quiet time on the Guardium system to avoid conflicts with long-running processes such as heavy reports, audit processes, backups, and imports.
- The exact time required for patch installation depends on database utilization, data distribution, and other considerations.
- Install patches in a top-down manner, first patching a central manager before patching aggregators and finally collectors.
To upload and install a patch using scp, issue the following CLI command: store system patch install scp
When the upload completes, you are automatically prompted to continue with the patch installation.
Install a patch using fileserver
To upload and install a patch using the Guardium fileserver:
- Initialize the fileserver using the following CLI command: fileserver [ip_address] where [ip_address] is the system being used to connect to the Guardium system.
- From a web browser, connect to the Guardium system.
- Click Upload Patch.
- Browse to select the patch file and then click Upload.
- Issue the following CLI command to install the patch: store system patch install system.
Distribute a patch
To distribute a patch from a central manager to managed units, one of the following must have taken place:
- The patch is installed on the central manager
- The patch has been made available on the central manager by running the following CLI command: store system patch available
Distribute the patch to managed units using the Central Management page on the central manager. Navigate to and click Patch Distribution.
Monitor and verify patch installation
You can monitor and verify the installation of patches in the following ways:
- Issue the following CLI command: show system patch install.
- Use the Central Management page on the CM: .