Contents
Network segment polling
Information about the structure of the network and devices in this network is received by the Administration Server through regular polling of cloud segments by using AWS API, Azure API, or Google API tools. Kaspersky Security Center uses this information to update the contents of the Unassigned devices and Managed devices folders. If you have configured devices to be moved to administration groups automatically, the detected devices are included in administration groups.
To allow the Administration Server to poll cloud segments, you must have the rights provided with an IAM role or IAM user account (in AWS), or with Application ID and password (in Azure), or with a Google client email, Google project ID, and private key.
You can add and delete connections, as well as set the polling schedule for each cloud segment.
Adding connections for cloud segment polling
To add a connection for cloud segment polling to the list of available connections:
- In the console tree, select the Device discovery → Cloud node.
- In the workspace of the window, click Configure polling.
A properties window opens containing a list of connections available for cloud segment polling.
- Click the Add button.
The Connection window opens.
- Specify the name of the cloud environment for the connection that will be used for further polling of the cloud segment:
If you selected AWS, specify the following settings:
The Cloud Environment Configuration Wizard allows you to specify only a single AWS IAM access key. Subsequently, you can specify more connections to manage other cloud segments.
If you selected Azure, specify the following settings:
- Connection name
- Azure Application ID
- Azure Subscription ID
- Azure Application password
- Azure storage account name
- Azure storage access key
If you selected Google Cloud, specify the following settings:
- If you want, select Set polling schedule and change the default settings.
The connection is saved in the application settings.
After the new cloud segment is polled for the first time, the subgroup corresponding to that segment appears in the Managed devices\Cloud administration group.
If you specify incorrect credentials, no instances will be found during cloud segment polling and a new subgroup will not appear in the Managed devices\Cloud administration group.
Deleting connections for cloud segment polling
If you no longer have to poll a specific cloud segment, you can delete the connection corresponding to that segment from the list of available connections. You can also delete a connection if, for example, permissions to poll a cloud segment have been transferred to another AWS IAM user with a different key.
To delete a connection:
- In the console tree, select the Device discovery → Cloud node.
- In the workspace of the window, select Configure polling.
A window opens containing a list of connections available for cloud segment polling.
- Select the connection that you want to delete and click the Delete button in the right part of the window.
- In the window that opens, click the OK button to confirm your selection.
If you are deleting connections from the list of available connections, the devices that are in the corresponding segments are automatically deleted from the corresponding administration groups.
Configuring the polling schedule
Cloud segment polling is performed according to schedule. You can set the polling frequency.
The polling frequency is automatically set at 5 minutes by the Cloud Environment Configuration Wizard. You can change this value at any time and set a different schedule. However, it is not recommended to configure polling to run more frequently than every 5 minutes, because this could lead to errors in the API operation.
To configure a cloud segment polling schedule:
- In the console tree, select the Device discovery → Cloud node.
- In the workspace, click Configure polling.
The cloud properties window opens.
- In the list, select the connection you want and click the Properties button.
The connection properties window opens.
- In the properties window, click the Set polling schedule link.
The Schedule window opens.
- Define the following settings:
- Scheduled start
Polling schedule options:
- Run missed tasks
- Scheduled start
- Click OK to save the changes.
The polling schedule is configured and saved.