Bigfix Monthly Updates

We use Bigfix to push common software updates out on a monthly schedule, usually as close to the 1st of the month as possible. This document explains how to do that.

A Primer On Baselines

A fixlet or task essentially addresses one issue at at time.  However, a baseline is a collection of fixlets that can be applied to a set of endpoints.  The a baseline has its own relevance to determine if it should be applied to an endpoint, but the relevance for each included fixlet determines whether that fixlet is actually applied.  You can have instances where one, several, or no fixlets are applied through a given baseline.

As the name implies, baselines are typically used to apply some sort of baseline set of updates, installs, or settings to endpoints.  I'm sure I'm not using it to its fullest potential, but it is a convenient way to apply a set of updates to our endpoints.

To get to the baselines, in the menu pane go to Sites/Custom Sites/Pharmacy/Baselines.

baselines

The baseline I use to apply updates monthly is called "Monthly Software Updates" (baseline pane).  When I update the list of fixlets to apply, I usually update the baseline name to include the month and year this baseline is applied to.  That way I can easily see in my Actions list when the baseline was initiated.

In the bottom pane you can view details for the selected baseline, including components (included fixlets), applicable computers, and others.  Feel free to include or exclude any fixlets in the components list that you deem applicable.  WARNING: Bigfix does include some Windows and Office fixlets.  I have decided to not include OS and office suite updates since there is no good way to test them and it can be difficult to understand what exactly the update is trying to fix.  We also have Windows endpoints configured to do their own updates anyway which should include Office updates.  Feel free to change this practice if you are comfortable with Bigfix handling those updates.

Notice in the fixlets list there are messages is red text.  "source fixlet differs" usually means that there is a newer version of the fixlet available.  You may see other messages.  Usually they indicate that the fixlet needs to be updated.  Even if there is no message, it's a good idea to review them all when setting up for the new round of updates each month.

Modifying The Baseline For Monthly Updates

  1. Select the Monthly Baseline, right-click and Edit.

  2. The baseline editor appears in a separate window.

  3. To simplify the process of adding a fixlet to a baseline, I created a series of custom filters that look for specific fixlets.  Otherwise you end up searching through a potentially long list of fixlets for what you want.  
    adding a baseline

    Using Apple iTunes as an example, click on the custom filter in the main Bigfix window, then right-click the fixlet you want and add it to an existing baseline (the Monthly Software Updates baseline).  
    added fixlet

  4. A couple of things to note when you add a fixlet to a baseline in this way.
    1. The fixlet is added to the end of the component list.  I'm not aware of any way to force it to sort the fixlet list.
    2. Fixlets are added to the first component group in the baseline ("Monthly Update Fixlets" in this baseline).  I'm not aware of any way to force the fixlet into a different component group should you want to organize them in some way in the future.

  5. When you're all done adding fixlets to the baseline:
    1. Delete the older ones by clicking the red X in those rows.
    2. Make sure all of the fixlets are set to their default action in the drop down box.  This will usually be "Action 1 (Default)".  Yes, depending on need fixlets can have multiple actions defined with one (not necessarily Action 1) of them being the default.

  6. In the "Edit Baseline" window click OK to save your changes.

  7. To run the baseline, click its "Take Action" tab and fill in the parameters just as you would with any other fixlet.  When you select the endpoints or target computers, I would recommend that you select "Dynamically by Property" and choose BF_Department = Pharmacy to make sure the baseline is directed at ALL of the endpoints in our department.  Relevance in each component fixlet will determine if that particular fixlet is applied to the endpoint.

A Word On Custom Filters

You can use custom filters for a variety of purposes.  In the context of a baseline, I'm using them to easily find fixlets I want to include.  To create a custom filter, just right-click "Custom Filters" in the menu pane and then "Create".  I have a sample filter below to use as a guide.
custom filter window

Here we're looking for the most recent fixlet available for updating the Windows version of Zoom.

  1. Name: Give your filter a meaningful name that will help you to remember what it's looking for. This is what will appear in the "Custom Filters" list.
  2. Include: You can include many different Bigfix objects, but right now all we're interested in is fixlets.
  3. With: This defines how all the conditions below are logically evaluated. "All" means "all conditions must be true (and), "Any" means if any one or more are true (or).  There is no way I know of to define more complex logical evaluations.
  4. Now you can list all the conditions for selecting a fixlet. They are all arranged in "field", "operator", "value" order.
    1. Field: The drop down box has several fields you can choose.  Name, Source and Site are the ones I've used the most, but others may be useful as well. 
    2. Operator:  You're limited to (does not) contain and (does not) equal.  "Contain" looks for your value as a substring in a given field; "Equal" looks for an exact match.
    3. Value: This is what you're looking for.
    4. +/-: The "-" button deletes a condition; the "+" adds a new one immediately below.
  5. Click Create/Update to save the filter.
  6. One common condition I use in my fixlet filters is "Name does not contain (Superseded)".  Older fixlets always contain the string "(Superseded)" in the name.  The newest version typically doesn't.  Therefore I can use this to filter out older versions and just focus on the newer ones.
  7. Use additional conditions to narrow your list of fixlets to choose from. 


Keywords:
bigfix tem tivoli endpoint manage update monthly 
Doc ID:
149639
Owned by:
Nick Z. in Pharmacy IIT
Created:
2025-04-07
Updated:
2026-07-22
Sites:
School of Pharmacy Instructional & Information Technology