Chapter 2. Getting started using the compliance service


This section describes how to configure your RHEL systems to report compliance data to the Insights for RHEL application. This installs necessary additional components such as the SCAP Security Guide (SSG), which is used to perform the compliance scan.

Prerequisites

  • The Insights client is deployed on the system.
  • You must have root privileges on the system.

Procedure

  1. Check the version of RHEL on the system:

    Copy to Clipboard Toggle word wrap
    [user@insights]$ ​​cat /etc/redhat-release
  2. Review the Insights Compliance - Supported configurations article and make note of the supported SSG version for the RHEL minor version on the system.

    Note

    Some minor versions of RHEL support more than one version of SSG. The Insights compliance service will always show results for the latest supported version.

  3. Check if the supported version of the SSG package is installed on the system:

    Example - for RHEL 8.4 run:

    Copy to Clipboard Toggle word wrap
    [root@insights]# dnf info scap-security-guide-0.1.57-3.el8_4
  4. If it is not already installed, install the supported version of SSG on the system.

    Example - for RHEL 8.4 run:

    Copy to Clipboard Toggle word wrap
    [root@insights]# dnf install scap-security-guide-0.1.57-3.el8_4
  5. Assign systems to policies using the Insights compliance service UI, or using insights-client commands in the CLI:

  6. After adding each system to the needed security policy, return to the system and run the compliance scan using:

    Copy to Clipboard Toggle word wrap
    [root@insights]# insights-client --compliance
    Note

    The scan can take 1-5 minutes to complete.

  7. Navigate to Security > Compliance > Reports to view results.
  8. Optional: Schedule the compliance jobs to run with cron.

Additional Resources

2.1. Setting up recurring scans for Insights services

To get the most accurate recommendations from Red Hat Insights services such as compliance and malware detection, you might need to manually scan and upload data collection reports to the services on a regular schedule.

Use the following insights-client commands to run the commands manually:

Copy to Clipboard Toggle word wrap
# insights-client --compliance
# insights-client --collector malware-detection

Currently, Insights does not have an automated scheduler to perform the scans for you, but you can configure a cron job to schedule automatic scans.

Important

Before you create a cron job, make sure that the commands work properly when you run them manually.

Prerequisites

  • The services you want to use (Compliance and Malware Detection) are configured and running on your system.

Procedure

  1. At the system prompt, issue the crontab -e command to edit the crontab file. This command opens your default text editor.

    Copy to Clipboard Toggle word wrap
    $ crontab -e
  2. Add a crontab entry for the service you want to run. For example:

    Copy to Clipboard Toggle word wrap
    10 20 * * * /bin/insights-client --compliance
    10 21 * * * /bin/insights-client --collector malware-detection

    In this example, the first command uploads a Compliance report to Insights every day at 20:10 local time. The second command uploads a malware detection report to Insights every day at 21:10 local time.

  3. Save the file and exit the text editor.
Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat, Inc.