Configuring Services
Use the Micro Focus Fortify WebInspect Enterprise Services Configuration Utility to configure or modify services associated with Fortify WebInspect Enterprise. Make sure the services are started even if you do not change any options.
To start the utility, click Start > All Programs > Fortify > Fortify WebInspect Enterprise 21.1.0 > WebInspect Enterprise Services Manager.
After the utility starts, the following buttons appear in the left column:
-
Scan Uploader Service - Handles the transfer of scans from Micro Focus Fortify WebInspect to Fortify WebInspect Enterprise.
-
Task Service - Monitors the queue for various tasks, including Micro Focus Fortify Software Security Center application version updates and Fortify Software Security Center issue synchronization (if applicable).
-
Scheduler Service - Handles the scheduling of scans, discovery scans, and smart updates.
Perform the procedures in the following sections after selecting each of these services.
Configuring the Scan Uploader Service
If the Fortify WebInspect Enterprise Scan Uploader Service was selected for installation as described in Installing the Fortify WebInspect Enterprise Server Software, Fortify WebInspect can scan a website and export the scan results to a location called a “dropbox.” The Scan Uploader Service accesses each dropbox periodically and, if files exist, it uploads those files to the Fortify WebInspect Enterprise Manager.
Service Status
This area of the interface displays the current status of the Scan Uploader service. You can start, stop, restart, or configure the service.
To configure the service:
-
Click Configure in the Service Status section.
The Configure Service window appears.
-
Select which credentials should be used for logging on to the service:
-
Local System account - This account is a predefined local account used by the service control manager (SCM). It has extensive privileges on the local computer, and acts as the computer on the network. A service that runs in the context of the Local System account inherits the security context of the SCM.
-
This account - An account identified by the credentials you specify.
-
-
If you select This account, enter an account name and password.
-
Click OK.
Fortify WebInspect Enterprise Configuration
This area of the interface displays the Fortify WebInspect Enterprise configuration.
To configure Fortify WebInspect Enterprise:
-
Click Configure in the WebInspect Enterprise Configuration section.
The WebInspect Enterprise Configuration window appears.
-
Enter the URL of the Fortify WebInspect Enterprise Manager.
-
Provide the Fortify WebInspect Enterprise Manager's authentication credentials.
-
To verify that the user name and password are correct, click Test.
-
If the Scan Uploader service uses a proxy, select Enable Proxy and provide the requested information.
-
Click OK.
Dropbox Configuration
Fortify WebInspect can scan a website and export the scan results to a location called a “dropbox.” The purpose of the Fortify WebInspect Enterprise Uploader service is to access each dropbox periodically and, if files exist, to upload those files to the Fortify WebInspect Enterprise Manager.
To create a dropbox:
-
Click Add in the Dropbox Configuration section.
The Configure Dropbox window appears.
-
Enter a dropbox name.
-
Enter the full path and name of the folder that will be used as the dropbox (or click Browse to select or create a folder).
-
Be sure to select or create a folder that will not be used for any other purpose.
-
Enter the application version that will be serviced by this dropbox.
-
Click OK.
Logging Configuration
This area of the interface displays current settings for the logging function.
To configure settings:
-
Click Configure in the Logging Configuration section.
The Logging Configuration widow appears.
-
The logging output is contained in
UploaderService_trace.log. To specify the location of the logs, choose one of the following:-
Default location
The default location is
C:\ProgramData\HP\WIE\UploaderService -
Enter location for log file
Type a path to the folder that will contain the logs, or click Browse to select a location.
-
-
For the logging level, choose either INFO (the default) or DEBUG (which records more data).
-
In the Max file size field, specify the maximum file size of a log file (in megabytes).
-
In the Number of backup files field, specify the maximum number of log files that will be retained.
When a log file reaches its maximum size, Fortify WebInspect Enterprise closes it and opens another file, repeating this process until the maximum number of log files is created. When that file is full, Fortify WebInspect Enterprise closes it, deletes the oldest file, and opens a new one. Files are named in sequence:
UploaderService_trace.log,UploaderService_trace.log.1, etc. -
Click OK.
Start the Service
Click Start in the Service Status section to start the service if it is not already running.
Configuring the Task Service
Configure the Task Service to monitor the queue for various tasks, including Fortify Software Security Center application version updates and Fortify Software Security Center issue synchronization (if applicable).
Service Status
This area of the interface displays the current status of the Task service, which handles background tasks such as Fortify Software Security Center application version updates and Fortify Software Security Center issue synchronization (if applicable). You can start, stop, restart, or configure the service.
To configure the service:
-
Click Configure in the Service Status section.
The Configure Service window appears.
-
Select which credentials should be used for logging on to the service:
-
Local System account - This account is a predefined local account used by the service control manager (SCM). It has extensive privileges on the local computer, and acts as the computer on the network. A service that runs in the context of the Local System account inherits the security context of the SCM.
-
This account - An account identified by the credentials you provide.
-
-
If you select This account, enter an account name and password.
-
Click OK.
Database Configuration
This area of the interface displays the database server name and database name.
To configure the database:
-
Click Configure in the Database Configuration section.
The Database Configuration window appears.
-
Enter a server name.
-
Specify the account under which Fortify WebInspect Enterprise will connect to the database.
-
Windows Authentication - The name and password specified in the Fortify WebInspect Enterprise Manager’s user account is used to authenticate to the database. When working in a domain environment, the Fortify WebInspect Enterprise Manager’s user account should be a domain account. When working in a workgroup environment, you must have the exact same user name and password on both the Fortify WebInspect Enterprise Manager and the database computers.
-
SQL Authentication - Enter the SQL Server user name and password.
-
-
Enter or select a database.
-
Click OK.
Logging Configuration
This area of the interface displays current settings for the logging function.
To configure settings:
-
Click Configure in the Logging Configuration section.
The Logging Configuration window appears.
-
The logging output is contained in
TaskService_trace.log. To specify the location of the logs, choose one of the following:-
Default location
The default location is
C:\ProgramData\HP\WIE\TaskService -
Enter location for log file
Type a path to the folder that will contain the logs, or click Browse to select a location.
-
-
For the logging level, choose either INFO (the default) or DEBUG (which records more data).
-
In the Max file size field, specify the maximum file size of a log file (in megabytes).
-
In the Number of backup files field, specify the maximum number of log files that will be retained.
-
When a log file reaches its maximum size, Fortify WebInspect Enterprise closes it and opens another file, repeating this process until the maximum number of log files is created. When that file is full, Fortify WebInspect Enterprise closes it, deletes the oldest file, and opens a new one. Files are named in sequence:
TaskService_trace.log,TaskService_trace.log.1, etc. -
Click OK.
Fortify Software Security Center Poll Interval
If Fortify WebInspect Enterprise is integrated with Fortify Software Security Center (SSC), this area of the interface determines how often Fortify WebInspect Enterprise contacts Fortify Software Security Center for updates.
-
In the SSC application version updates polling interval (in seconds) field, specify how frequently Fortify WebInspect Enterprise contacts Fortify Software Security Center to check for application version name changes or deletions.
-
In the SSC issue synchronization interval (in minutes) field, specify how frequently Fortify WebInspect Enterprise contacts Fortify Software Security Center to check for changes to audit information, comments, attachments, and “not an issue” and “suppressed” status.
-
Click Apply.
Start the Service
Click Start in the Service Status section to start the service if it is not already running.
Configuring the Scheduler Service
Configure the Scheduler Service to handle the scheduling of scans, discovery scans, and smart updates.
Service Status
This area of the interface displays the current status of the Scheduler service. You can start, stop, restart, or configure the service.
To configure the Scheduler service:
-
Click Configure in the Service Status section.
The Configure Service window appears.
-
Select which credentials should be used for logging on to the service:
-
Local System account - This account is a predefined local account used by the service control manager (SCM). It has extensive privileges on the local computer, and acts as the computer on the network. A service that runs in the context of the Local System account inherits the security context of the SCM.
-
This account - An account identified by the credentials you specify.
-
-
If you select This account, enter an account name and password.
-
Click OK.
Fortify WebInspect Enterprise Manager
If the Fortify WebInspect Enterprise Manager URL is changed using IIS or another tool, change the URL here as well.
Logging Configuration
This area of the interface displays current settings for the logging function.
To configure settings:
-
Click Configure in the Logging Configuration section.
The Logging Configuration window appears.
-
The logging output is contained in
Scheduler_trace.log. To specify the location of the logs, choose one of the following:-
Default location
The default location is
C:\ProgramData\HP\WIE\Scheduler -
Enter location for log file
Type a path to the folder that will contain the logs, or click Browse to select a location.
-
-
For the logging level, choose either INFO (the default) or DEBUG (which records more data).
-
In the Max file size field, specify the maximum file size of a log file (in megabytes).
-
In the Number of backup files field, specify the maximum number of log files that will be retained.
When a log file reaches its maximum size, Fortify WebInspect Enterprise closes it and opens another file, repeating this process until the maximum number of log files is created. When that file is full, Fortify WebInspect Enterprise closes it, deletes the oldest file, and opens a new one. Files are named in sequence:
Scheduler_trace.log,Scheduler_trace.log.1, etc.
Start the Service
Click Start in the Service Status section to start the service if it is not already running.
Post Configuration
After configuring the services, close the WebInspect Enterprise Services Configuration utility.