SCOM 2019 with multiple UNIX Resource Pools

Christian Redgewell 21 Reputation points
2020-09-21T06:00:28.053+00:00

I have an environment where I need 3 UNIX resource Pools for valid reasons, i.e. network and domain segmentation. So I have a primary Resource Pool with the bulk of our servers and then 2 other DMZ ones. These contain a number of Gateway Servers in each and all have different Unix Run As accounts for different subnets and domains. I am finding it fairly complex to work out which classes I should assign the Run as accounts to in the Run As profiles.

Has anyone done this before? I just need to assign the 3 accounts to the right areas, this is proving more difficult as we can't discover anything in the DMZ until we get this going. I can separate by group but my issue is more about assigning the run as profiles to the DMZ Gateway Servers correctly, as it errors on discovery and it is only erroring as I cannot distribute the account correctly.

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,421 questions
0 comments No comments
{count} votes

Accepted answer
  1. SChalakov 10,271 Reputation points MVP
    2020-09-21T07:30:06.107+00:00

    Hi @Christian Redgewell ,

    I have done this and I also described this in an answer here:

    Different accounts for different Linuxes

    You just need to group all your monitored UNIX/Linux Systems in each environment and target the group with the respective service account.
    I would recommend you to build a dynamic group, based on some criteria, so that you don't have to manage it afterwards, but a group with static members will do the job also. So in your case you will end up with 3 groups targeted by the different service accounts.
    I hope I was able to help you.

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)
    Best regards,
    Stoyan


1 additional answer

Sort by: Most helpful
  1. Berg, Ronald van den 46 Reputation points
    2020-09-21T07:27:49.977+00:00

    Did you consider creating a separate resourcepool per account group? That's how i do it.

    I assign the run-as accounts to the resourcepool and create a dynamic group that will contain all servers belonging to that group, the unix/linux computer class is then sufficient.
    The unix/linux profiles are then assigned to that dynamic group.

    I think i've tried assigning multiple accounts to the same pool once but then you get alerts since all accounts are tried to use against servers it does not have permissions to.