<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best Practices &amp;amp; Scripts for OS / CIS Hardening on Dynatrace Managed Clusters in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Best-Practices-amp-Scripts-for-OS-CIS-Hardening-on-Dynatrace/m-p/302819#M4838</link>
    <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;We are working on bringing our infrastructure into strict alignment with industry security standards (such as CIS Benchmarks, NIST, and DISA STIG). Our core objective is to apply a robust security posture to the underlying Linux operating systems hosting our Dynatrace Managed clusters.&lt;BR /&gt;&lt;BR /&gt;Since Dynatrace Managed deploys embedded components like Apache Cassandra, Elasticsearch, and its own NGINX gateway, aggressive out-of-the-box OS hardening can sometimes disrupt internal node communication or service permissions.&lt;BR /&gt;&lt;BR /&gt;I would appreciate guidance or shared experiences from the community on the following:&lt;BR /&gt;&lt;BR /&gt;1. Hardening Check Scripts/Commands: Do you utilize specific OpenSCAP profiles, Ansible playbooks, or custom bash scripts to audit and remediate the underlying OS without breaking Dynatrace cluster services?&lt;BR /&gt;&lt;BR /&gt;2. Component-Specific Exceptions: Are there specific CIS rules we should avoid or modify? For example, how do you handle constraints around the unprivileged dynatrace user/group, database auditing, or internal firewall settings?&lt;BR /&gt;&lt;BR /&gt;3.&amp;nbsp;Official Guidelines: Is there an updated, official technical guide or a list of supported hardening metrics specific to Dynatrace Managed environments?&lt;BR /&gt;&lt;BR /&gt;Any scripts, command snippets, or lessons learned from passing compliance audits with Dynatrace Managed would be incredibly helpful.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2026 06:16:39 GMT</pubDate>
    <dc:creator>PradeepGM</dc:creator>
    <dc:date>2026-08-05T06:16:39Z</dc:date>
    <item>
      <title>Best Practices &amp; Scripts for OS / CIS Hardening on Dynatrace Managed Clusters</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Best-Practices-amp-Scripts-for-OS-CIS-Hardening-on-Dynatrace/m-p/302819#M4838</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;We are working on bringing our infrastructure into strict alignment with industry security standards (such as CIS Benchmarks, NIST, and DISA STIG). Our core objective is to apply a robust security posture to the underlying Linux operating systems hosting our Dynatrace Managed clusters.&lt;BR /&gt;&lt;BR /&gt;Since Dynatrace Managed deploys embedded components like Apache Cassandra, Elasticsearch, and its own NGINX gateway, aggressive out-of-the-box OS hardening can sometimes disrupt internal node communication or service permissions.&lt;BR /&gt;&lt;BR /&gt;I would appreciate guidance or shared experiences from the community on the following:&lt;BR /&gt;&lt;BR /&gt;1. Hardening Check Scripts/Commands: Do you utilize specific OpenSCAP profiles, Ansible playbooks, or custom bash scripts to audit and remediate the underlying OS without breaking Dynatrace cluster services?&lt;BR /&gt;&lt;BR /&gt;2. Component-Specific Exceptions: Are there specific CIS rules we should avoid or modify? For example, how do you handle constraints around the unprivileged dynatrace user/group, database auditing, or internal firewall settings?&lt;BR /&gt;&lt;BR /&gt;3.&amp;nbsp;Official Guidelines: Is there an updated, official technical guide or a list of supported hardening metrics specific to Dynatrace Managed environments?&lt;BR /&gt;&lt;BR /&gt;Any scripts, command snippets, or lessons learned from passing compliance audits with Dynatrace Managed would be incredibly helpful.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 06:16:39 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Best-Practices-amp-Scripts-for-OS-CIS-Hardening-on-Dynatrace/m-p/302819#M4838</guid>
      <dc:creator>PradeepGM</dc:creator>
      <dc:date>2026-08-05T06:16:39Z</dc:date>
    </item>
  </channel>
</rss>

