Create a Local Script (Remediation) Action

Remediation script-path validation and remediation log-path validation are separate controls. Script paths are restricted by the Controller, while log-path allowlisting is enforced by the target Machine Agent starting with Machine Agent 26.8.0.

To create a remediation action:

  1. Access the Create Action pane. See Create and Modify Actions in Actions.
  2. Select Run a script or executable on problematic Nodes in the Create Action pane and click OK.
  3. After entering a name for the action, in the field that terminates the Relative path to script entry, enter the path to the executable script. The remediation script must be stored in a subdirectory named local-scripts under the Machine Agent installation directory. The script path is validated separately from log-file paths. The following paths are valid:
    CODE
    ${machine.agent.directory}/local-scripts/runMe.sh ${machine.agent.directory}/local-scripts/johns_scripts/runMe.sh ${machine.agent.directory}/local-scripts/ops/johns_scripts/runMe.sh
  4. In Absolute paths to log files, enter each log file that the action should collect. If remediation log-path validation is enabled on the target Machine Agent, each path must resolve within a directory configured in that Agent's local allowlist. A rejected path is not uploaded, but rejection alone does not fail an otherwise successful action. Review the Machine Agent log for rejection details. See Machine Agent Configuration Properties.
    Note: If remediation log-path validation is disabled on the target Machine Agent, the action retains its legacy log-file collection behavior. To restrict collection, enable remediation log-path validation and configure the allowed directory roots on the target Machine Agent.
  5. Enter the timeout period for the script process in minutes.
  6. To mandate an approval before the script action can be started, select the Require approval before executing this Action check box and enter the email address of the individual or group that is authorized to approve the action. See Actions Requiring Approval for more information.