Instance Group Discovery

Microsoft.AdvancedThreatAnalytics.1_8.InstancesGroup.Discovery (Discovery)

Discovers Microsoft ATA 1.8 instances for group membership.

Knowledge Base article:

Summary

This discovery discovers instances of Microsoft ATA classes and adds them to the Microsoft ATA Instances Group.

Element properties:

TargetMicrosoft.AdvancedThreatAnalytics.1_8.InstancesGroup
EnabledTrue
RemotableFalse

Object Discovery Details:

Discovered Classes and their attribuets:

Member Modules:

ID Module Type TypeId RunAs 
InstanceGroupPopulationDataSource DataSource Microsoft.SystemCenter.GroupPopulator Default

Source Code:

<Discovery ID="Microsoft.AdvancedThreatAnalytics.1_8.InstancesGroup.Discovery" Enabled="true" ConfirmDelivery="false" Priority="Normal" Remotable="true" Target="Microsoft.AdvancedThreatAnalytics.1_8.InstancesGroup">
<Category>Discovery</Category>
<DiscoveryTypes>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_8.Center"/>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_8.Gateway"/>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_8.Database"/>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_8.Service"/>
</DiscoveryTypes>
<DataSource ID="InstanceGroupPopulationDataSource" TypeID="SC!Microsoft.SystemCenter.GroupPopulator">
<RuleId>$MPElement$</RuleId>
<GroupInstanceId>$MPElement[Name="Microsoft.AdvancedThreatAnalytics.1_8.InstancesGroup"]$</GroupInstanceId>
<MembershipRules>
<MembershipRule>
<MonitoringClass>$MPElement[Name="Microsoft.AdvancedThreatAnalytics.1_8.Center"]$</MonitoringClass>
<RelationshipClass>$MPElement[Name="MSIL!Microsoft.SystemCenter.InstanceGroupContainsEntities"]$</RelationshipClass>
</MembershipRule>
<MembershipRule>
<MonitoringClass>$MPElement[Name="Microsoft.AdvancedThreatAnalytics.1_8.Gateway"]$</MonitoringClass>
<RelationshipClass>$MPElement[Name="MSIL!Microsoft.SystemCenter.InstanceGroupContainsEntities"]$</RelationshipClass>
</MembershipRule>
<MembershipRule>
<MonitoringClass>$MPElement[Name="Microsoft.AdvancedThreatAnalytics.1_8.Database"]$</MonitoringClass>
<RelationshipClass>$MPElement[Name="MSIL!Microsoft.SystemCenter.InstanceGroupContainsEntities"]$</RelationshipClass>
</MembershipRule>
<MembershipRule>
<MonitoringClass>$MPElement[Name="Microsoft.AdvancedThreatAnalytics.1_8.Service"]$</MonitoringClass>
<RelationshipClass>$MPElement[Name="MSIL!Microsoft.SystemCenter.InstanceGroupContainsEntities"]$</RelationshipClass>
</MembershipRule>
</MembershipRules>
</DataSource>
</Discovery>