BigFix Endpoint Overview

This is an overview of how to work with endpoints in the BigFix console.

Installing The Client

  1. DoIT provides clients for Windows, MacOS, and certain kinds of Linux OS's.  Rather than go into a lot of detail here, I will redirect the reader to BigFix - Obtaining Client Installers for information on downloading, configuring, and installing the client. 

  2. Campus has a custom field called "BF_Department" that is uses to limit your access to only those endpoints in your department.  However, there is nothing in the client installer itself that will identify an endpoint as being in your department.  You must edit your installers so that they define a value for "BF_Department".  The link above can point you to KB documents that explain how to do that.
    1. Our BF_Department value has been, and probably ever shall be, "Pharmacy".
    2. If you do not define BF_Department in your installers, or do so incorrectly, the endpoint running the client will be tagged as "lost" in the campus console.  It will also not appear in your console. DoIT does send email monthly for lost computers (it's a "Lost Computer Audit").  You should review the endpoints listed in that report and have the campus BF operators update the BF_Department value for you if you find any Pharmacy endpoints in it.  They should then appear in the "Computers" list in your console.
    3. You can also define a "BF_Subdepartment" value in your installers.  Rather than try to determine this when I install the client or create many different versions of the installers for each BF_Subdepartment that I might want, I just use "NEW_CLIENT" as the value.  When I see that in the console, I can then edit the endpoint's properties and give BF_Subdepartment any value I want. 
      1. Typically I use "facstaff" for general faculty/staff computers.
      2. I have also used "phi_workstation_" followed by a PI NetID for endpoints approved to access restricted data.  This is helpful when monitoring those endpoints for compliance.
      3. The actual pharmacy relay has a BF_Subdepartment value of "Relay".
      4. I've also used "Server" for endpoints that are actually servers of some kind (such as the print server).
      5. Any others that you might find are probably artifacts from a bygone era and should probably be updated.
      6. You can use BF_Subdepartment in whatever way you best see fit.  It's just a field that can take any string value.
    4. It's probably not necessary to get and update installers for each new version of the client.  You can work with an older client/installer version for a long time since you can always update it via the console.  However, as a matter of best practice you may want to get and modify installers once a year or whenever there is a major version number change.

  3. Optionally, you can also configure your departmental relay in the .msi config (Registry3 record) or clientsettings.cfg file (_RelayServer1) but usually I just make sure it's defined once the endpoint appears in the console.  I do have a fixlet policy running that checks this and sets the correct value if needed.
    1. In the console, the relay should be "tem.pharmacy.wisc.edu:52311" for all endpoints except for the relay itself.
    2. The relay endpoint should be set to "bifrost.doit.wisc.edu:52311".  If it is ever set to "tem.pharmacy.wisc.edu" weird things happen.
    3. If you are setting the relay in the client configuration file or msi editor, the value is "http://tem.pharmacy.wisc.edu:52311/bfmirror/downloads/ ".  But again, I don't usually bother with it until after it appears in the console.

  4. Once you have the client installed and the service is running in the background, it will take a few minutes for it to appear in your console.  I'd give it at least five minutes to report in.  I'd say after 15 you may want to start troubleshooting.

  5. Some things to look at if the endpoint doesn't appear in your console in a reasonable amount of time.
    1. Check the running services on the endpoint.  There should be something called "BESClient" on Windows or "BESAgent"/"BESClientUI" on MacOS.
    2. Does the endpoint have an active network connection?
    3. Did you configure the installer to set BF_Department to "Pharmacy"?  Did you save/update/use that installer?

Relays

The relay is where BigFix keeps executable files for use in fixlets.  There are several campus-level relays, which you really shouldn't use.  There can be performance costs if everybody on campus used them.  You should make sure all of our endpoints use "tem.pharmacy.wisc.edu" and that port 52311 is open on that server.  The campus relays pass needed files down to department relays when needed. 

At the time of this writing, "tem.pharmacy.wisc.edu" points to the same server as "rtvm.pharmacy.wisc.edu".  Both RT and the BigFix relay service are running on the same VM.

Computers

  1. Click on the "Computers" menu option to display all of the endpoints registered in BigFix in the top pane of the console.
    1. The console can only display those endpoints that have a BigFix client installed and running on them.  If you are using BigFix as an inventory tool, you will have to make sure that all endpoints (or workstations) have the client.
    2. Endpoints displayed in light gray are currently not communicating with the console.  There can be several reasons for this and usually is not a cause for alarm.  You can still click on those endpoints and the console will display that most recent information it has for those endpoints.

  2. Use the Search box in the upper right corner to look for a specific endpoint or set of endpoints. 
    1. The console will look for the text you enter in all the column except for the Last Report Time.
    2. You do not have to enter a complete string - the search will return all endpoints where any string column contains the search value.  For example, if you enter "phi", the console would return all endpoints where any of the columns contain "phi": Computer Name, BF_Department, User_Name, BF_Subdepartment, OS, etc.  
    3. As with other Windows applications, you can click on the column header to sort the list by those values.
    4. You can right-click on the headers to add or remove columns.

  3. The bottom pane will display the properties of the selected endpoint in the Summary tab.  You can get information about networking, Active Directory (if applicable), installed applications, running services, and much more.  To create reports based on or to display these properties, you should probably use the BigFix Web Reporting tool (BigFix - Web Reports - Accessing the Console ).

  4. I have not used the other Properties tabs very much.

  5. If you right-click on an endpoint, you can change the values of some of its BigFix settings including custom fields such as BF_Department and BF_Subdepartment.  Changing the BF_Subdepartment and Relay address have been the most useful.

Retiring Computers

When a computer (or endoint) is no longer in service, you have to manually remove it from the console.  You do this by right-clicking it and then select "Remove From Database".  That's it - it's out of BigFix!  Note that if you mistakenly remove the wrong endpoint, it will reappear the next time it turns on and checks back into the console.  Removing an endpoint from the BigFix database does not initiate any process to remove the client from the endpoint.

You will also notice that some endpoints in the console have not reported in several months or maybe even over a year.  You should monitor those endpoints as this probably means that they are no longer used and should be removed from the BigFix console as well as Active Directory,  Qualys, and Cisco Secure Endpoint.  Each installed client consumes one license and we can help control costs by removing unused assets in a timely fashion.



Keywords:
BigFix endpoint computer management tem tivoli install client 
Doc ID:
149155
Owned by:
Nick Z. in Pharmacy IIT
Created:
2025-03-17
Updated:
2026-07-22
Sites:
School of Pharmacy Instructional & Information Technology