Configuring the IIS metabase rule

The IIS Metabase audit rule allows you to select IIS Metabase objects and objects folders to compare in your audit. The audit will capture IIS Metabase object property information such as ID, name, path, attributes, and so on.

If you are checking ACLs for Metabase rule, and the user and group ACL does not exist, then after the audit is run and after remediation, if user and group does not exist on target a temporary user and group will be created as unknown name. The next time you run the audit, it shows up as unknown, which shows name other than the source user.

Additionally, if you create an IIS Metabase rule from a source server and the metabase object selected for the rule inherits its values from a parent Metabase object, differences will show after an audit is run. For example, if you remediate once and then rerun the audit, if the source key was not inherited and the attribute has an IED when it gets created on target server, the object will be created based on parent key inheritance. When you rerun the audit, the results will show the IED as a difference for the object's attribute.

For more information on remediation, see Audit results .

Note If you want to audit Microsoft IIS 7.0 on a Windows Server 2008 server, create and configure the IIS 7.0 rule in your audit. See Configuring the IIS 7.0 rule.

To configure IIS Metabase rules:

  1. Create the new audit using one of the methods for creating an audit listed at Creating an audit . (If you want to create this rule for a snapshot specification, see Creating a snapshot specification .)
  2. Select an Audit Source: Server, Snapshot, Snapshot Specification, or No Source. (Some audit rules, such as Application Configuration and Windows User’s and Groups, must have a source.)
  3. In the Audit window, from the Views pane, select Rules > IIS Metabase.
  4. In the content pane of the Audit window, expand the top level node in the Available for Audit section and select an IIS Metabase folder or object to create a rule for. (You can select any metabase folder or object for the rules, but you cannot select the root folder to use as a rule.)
  5. Click the right arrow button to move the IIS Metabase folder or object into the Selected for Audit section. All items you select will be used to audit or snapshot the target server.
  6. To finish configuring the audit, set the target servers, the schedule, and the notification for the audit.
  7. To save the audit, from the File menu, select Save. You can also save the Audit as a policy. For more information, see Saving an audit or a snapshot specification as an audit policy.
  8. To run the audit, from the Actions menu, select Run Audit. For more information about running an audit, seeCreating an audit policy .