Skip to main content

Enabling System Guard

System Guard monitors for deviations in hardware inventory for ThinkSystem servers with XCC2.

About this task

Monitored inventory includes processors, memory, PCI adapters, drives, system board and risers. Changes in firmware levels and configuration settings are not detected.

When System Guard is enabled, a snapshot of the hardware inventory is taken as trusted reference for each selected device. When a device is rebooted, the baseboard management controller in the device collects the current system configuration and compares it to the snapshot. When a deviation is detected for one or more components, System Guard raises an event. If a deviation is detected for a processor or memory, System Guard raises an event, and optionally prevents the server from booting into the OS.

Procedure

To enable System Guard on one more servers with XCC2, complete the following steps.

  1. From the XClarity Administrator menu, click Hardware > Servers. The Servers page is displayed with a tabular view of all managed servers.
  2. Select one or more servers with XCC2.
  3. Click All actions > Security > Enable System Guard to display the Enable System Guard dialog.
  4. Choose the action to take when System Guard is enabled, an inventory change is detected, and the server becomes non-compliant.
    • Enable, keep system default behavior. The current behavior is used. The default behavior is to generate an event.

    • Enable, prevent OS booting when noncompliant. An event is raised. If you attempt to boot into the OS, you are warned if System Guard detects configuration changes to processors or memory. In this case, you are prompted to log into the baseboard management controller if the changes are unexpected; otherwise, you can continue the boot or shutdown process. If you do not respond within 5 minutes, the server is shut down by default.

    • Enable, generate event when noncompliant. An event is raised, but no other action is taken.

  5. Click Apply.

    A job is created to create inventory snapshots for the selected server. You can monitor the progress of the job from the jobs log. From the XClarity Administrator menu, click Monitoring > Jobs. For more information about the job log, see Monitoring jobs.

After you finish

To disable System Guard on selected servers, click All actions > Security > Disable System Guard, and then click Apply.