TKGi CIS and STIG benchmarks are configured in Compliance Scanner for VMware Tanzu as per https://techdocs.broadcom.com/us/en/vmware-tanzu/compliance/compliance-scanner-for-tanzu/1-3/compliance-tanzu/installing.html
After running the scans, no reports are generated for any TKGi node.
"Error: dial tcp <TKGi VM IP>:28893: i/o timeout"
errors are observed in oscap_store VM's /var/vcap/data/sys/log/scan_results
logs.
This can be caused by:
# bosh -d <tkgi-deployment-name> is --ps
# ps -elf | grep scanner
0 S vcap 9274 1 0 70 -10 1091 0 - Nov25 ? 00:00:00 /bin/bash /var/vcap/jobs/config_scanner/bin/scanner_web_ctl start
0 S vcap 9276 9274 0 70 -10 418841 0 - Nov25 ? 00:00:00 /var/vcap/jobs/config_scanner/packages/scanner/scanner_web --config /var/vcap/jobs/config_scanner/conf/scanner_web.conf
0 S root 9297 1 0 70 -10 1091 0 - Nov25 ? 00:00:00 /bin/bash /var/vcap/jobs/config_scanner/bin/scanner_daemon_ctl start
0 S root 9300 9297 0 70 -10 418735 0 - Nov25 ? 00:00:00 /var/vcap/jobs/config_scanner/packages/scanner/scanner_daemon --config /var/vcap/jobs/config_scanner/conf/scanner_daemon.conf
/var/vcap/sys/log/config_scanner
directory within the VMs./var/vcap/data/sys/log/scan_results
logs. See if you find any errors as follows: "Error: dial tcp <TKGi VM IP>:28893: i/o timeout"
/var/vcap/jobs/config_scanner/conf/scanner_web.conf
# netstat -putan | grep 28893
tcp 0 0 0.0.0.0:28893 0.0.0.0:* LISTEN 9274/scanner_web