TKGi CIS and STIG benchmarks are configured in Compliance Scanner for VMware Tanzu as per https://techdocs.broadcom.com/us/en/vmware-tanzu/compliance/compliance-scanner-for-tanzu/1-3/compliance-tanzu/installing.html
After running the scans, no reports are generated for any TKGi node.
"Error: dial tcp <TKGi VM IP>:28893: i/o timeout" errors are observed in oscap_store VM's /var/vcap/data/sys/log/scan_results logs.
This can be caused by:
# bosh -d <tkgi-deployment-name> is --ps# ps -elf | grep scanner0 S vcap 9274 1 0 70 -10 1091 0 - Nov25 ? 00:00:00 /bin/bash /var/vcap/jobs/config_scanner/bin/scanner_web_ctl start0 S vcap 9276 9274 0 70 -10 418841 0 - Nov25 ? 00:00:00 /var/vcap/jobs/config_scanner/packages/scanner/scanner_web --config /var/vcap/jobs/config_scanner/conf/scanner_web.conf0 S root 9297 1 0 70 -10 1091 0 - Nov25 ? 00:00:00 /bin/bash /var/vcap/jobs/config_scanner/bin/scanner_daemon_ctl start0 S root 9300 9297 0 70 -10 418735 0 - Nov25 ? 00:00:00 /var/vcap/jobs/config_scanner/packages/scanner/scanner_daemon --config /var/vcap/jobs/config_scanner/conf/scanner_daemon.conf/var/vcap/sys/log/config_scanner directory within the VMs./var/vcap/data/sys/log/scan_results logs. See if you find any errors as follows: "Error: dial tcp <TKGi VM IP>:28893: i/o timeout"/var/vcap/jobs/config_scanner/conf/scanner_web.conf# netstat -putan | grep 28893tcp 0 0 0.0.0.0:28893 0.0.0.0:* LISTEN 9274/scanner_web