Kaspersky Security Center Cloud Console

Device tags

Kaspersky Security Center Cloud Console enables you to tag devices. A tag is the label of a device that can be used for grouping, describing, or finding devices. Tags assigned to devices can be used for creating selections, for finding devices, and for distributing devices among administration groups.

You can tag devices manually or automatically. You may use manual tagging when you want to tag an individual device. Auto-tagging is performed by Kaspersky Security Center Cloud Console in accordance with the specified tagging rules.

Devices are tagged automatically when specified rules are met. An individual rule corresponds to each tag. Rules are applied to the network properties of the device, operating system, applications installed on the device, and other device properties. For example, if your network includes devices running Windows, Linux, and macOS, you can set up a rule that will assign the [Linux] tag to all Linux-based devices. Then, you can use this tag when creating a device selection; this will help you sort all Linux-based devices and assign them a task. A tag is automatically removed from a device in the following cases:

  • When the device stops meeting conditions of the rule that assigns the tag.
  • When the rule that assigns the tag is disabled or deleted.

The list of tags and the list of rules on each Administration Server are independent of all other Administration Servers, including a primary Administration Server or subordinate virtual Administration Servers. A rule is applied only to devices from the same Administration Server on which the rule is created.

See also:

Managing client devices

Scenario: Configuring network protection

Page top
[Topic 175848]

Creating a device tag

To create a device tag:

  1. In the main menu, go to Assets (Devices)TagsDevice tags.
  2. Click Add.

    A new tag window opens.

  3. In the Tag field, enter the tag name.
  4. Click Save to save the changes.

The new tag appears in the list of device tags.

Page top
[Topic 175850]

Renaming a device tag

To rename a device tag:

  1. In the main menu, go to Assets (Devices)TagsDevice tags.
  2. Click the name of the tag that you want to rename.

    A tag properties window opens.

  3. In the Tag field, change the tag name.
  4. Click Save to save the changes.

The updated tag appears in the list of device tags.

Page top
[Topic 175855]

Deleting a device tag

To delete a device tag:

  1. In the main menu, go to Assets (Devices)TagsDevice tags.
  2. In the list, select the device tag that you want to delete.
  3. Click the Delete button.
  4. In the window that opens, click Yes.

The device tag is deleted. The deleted tag is automatically removed from all of the devices to which it was assigned.

The tag that you have deleted is not removed automatically from auto-tagging rules. After the tag is deleted, it will be assigned to a new device only when the device first meets the conditions of a rule that assigns the tag.

The deleted tag is not removed automatically from the device if this tag is assigned to the device by an application or Network Agent. To remove the tag from your device, use the klscflag utility.

Page top
[Topic 175856]

Viewing devices to which a tag is assigned

To view devices to which a tag is assigned:

  1. In the main menu, go to Assets (Devices)TagsDevice tags.
  2. Click the View devices link next to the tag for which you want to view assigned devices.

    You will be redirected to the Managed devices section of the main menu, with the devices filtered by the tag for which you clicked the View devices link.

  3. If you want to return to the list of device tags, click the Back button of your browser.

After you view the devices to which the tag is assigned, you can either create and assign a new tag or assign the existing tag to other devices. In this case, you have to remove the filter by tag, select the devices, and then assign the tag.

Page top
[Topic 175859]

Viewing tags assigned to a device

To view tags assigned to a device:

  1. In the main menu, go to Assets (Devices) → Managed devices.
  2. Click the name of the device whose tags you want to view.
  3. In the device properties window that opens, select the Tags tab.

The list of tags assigned to the selected device is displayed. In the Tag assigned column you can view how the tag was assigned.

You can assign another tag to the device or remove an already assigned tag. You can also view all device tags that exist on the Administration Server.

You can also view tags assigned to a device in the command line, by using the klscflag utility.

To view tags assigned to a device in the command line, run the following command:

klscflag -ssvget -pv 1103/1.0.0.0 -s KLNAG_SECTION_TAGS_INFO -n KLCONN_HOST_TAGS -svt ARRAY_T -ss "|ss_type = \"SS_PRODINFO\";"

Page top
[Topic 175862]

Tagging devices manually

To assign a tag to a device:

  1. View tags assigned to the device to which you want to assign another tag.
  2. Click Add.
  3. In the window that opens, do one of the following:
    • To create and assign a new tag, select Create new tag, and then specify the name of the new tag.
    • To select an existing tag, select Assign existing tag, and then select the necessary tag in the drop-down list.
  4. Click OK to apply the changes.
  5. Click Save to save the changes.

The selected tag is assigned to the device.

To assign a tag to several devices:

  1. In the main menu, go to Assets (Devices) Managed devices.
  2. Select the devices to which you want to assign a tag.
  3. Click Tags, and then select Assign from the drop-down list.
  4. In the window that opens, select a tag from the drop-down list.

    If necessary, you can select several tags.

    You can also do the following:

    • Edit the name of a tag by clicking the Edit (A pencil.) icon.

      Specify the new name of the tag, and then click the Save button.

      Note that the tag will also be renamed in the list of device tags.

    • Delete a tag by clicking the Delete (Trash can.) icon.

      In the window that opens, click Delete.

      Note that the tag will also be deleted from the Administration Server.

  5. Click the Save button.

The tags are assigned to the selected devices. You can remove the assigned tags.

Page top
[Topic 175860]

Removing assigned tags from devices

The unassigned device tag is not deleted. If you want, you can delete it manually.

You cannot manually remove tags assigned to the device by applications or Network Agent. To remove these tags, use the klscflag utility.

To remove a tag from a device:

  1. In the main menu, go to Assets (Devices) → Managed devices.
  2. Click the name of the device whose tags you want to view.
  3. In the device properties window that opens, select the Tags tab.
  4. Select the check box next to the tag that you want to remove.
  5. At the top of the list, click the Unassign tag? button.
  6. In the window that opens, click Yes.

The tag is removed from the device.

To remove tags from several devices:

  1. In the main menu, go to Assets (Devices) Managed devices.
  2. Select the devices whose tags you want to remove.
  3. Click Tags, and then select Unassign from the drop-down list.
  4. In the window that opens, select the check boxes next to the tags that you want to remove.

    The window displays all tags assigned to all the devices that you selected at step 2.

  5. Click the Save button.

The tags are removed from the devices.

Page top
[Topic 175861]

Viewing rules for tagging devices automatically

To view rules for tagging devices automatically,

Do any of the following:

  • In the main menu, go to Assets (Devices) → TagsAuto-tagging rules.
  • In the main menu, go to Assets (Devices) → TagsDevice tags, and then click the Set up auto-tagging rules link.
  • View tags assigned to a device and then click the Settings button.

The list of rules for auto-tagging devices appears.

Page top
[Topic 175849]

Editing a rule for tagging devices automatically

To edit a rule for tagging devices automatically:

  1. View rules for tagging devices automatically.
  2. Click the name of the rule that you want to edit.

    A rule settings window opens.

  3. Edit the general properties of the rule:
    1. In the Rule name field, change the rule name.

      The name cannot be more than 256 characters long.

    2. Do any of the following:
      • Enable the rule by switching the toggle button to Rule enabled.
      • Disable the rule by switching the toggle button to Rule disabled.
  4. Do any of the following:
    • If you want to add a new condition, click the Add button, and specify the settings of the new condition in the window that opens.
    • If you want to edit an existing condition, click the name of the condition that you want to edit, and then edit the condition settings.
    • If you want to delete a condition, select the check box next to the name of the condition that you want to delete, and then click Delete.
  5. Click OK in the conditions settings window.
  6. Click Save to save the changes.

The edited rule is shown in the list.

Page top
[Topic 175967]

Creating a rule for tagging devices automatically

To create a rule for tagging devices automatically:

  1. View rules for tagging devices automatically.
  2. Click Add.

    A new rule settings window opens.

  3. Configure the general properties of the rule:
    1. In the Rule name field, enter the rule name.

      The name cannot be more than 256 characters long.

    2. Do one of the following:
      • Enable the rule by switching the toggle button to Rule enabled.
      • Disable the rule by switching the toggle button to Rule disabled.
    3. In the Tag field, enter the new device tag name or select one of the existing device tags from the list.

      The name cannot be more than 256 characters long.

  4. In the conditions section, click the Add button to add a new condition.

    A new condition settings window open.

  5. Enter the condition name.

    The name cannot be more than 256 characters long. The name must be unique within a rule.

  6. Set up the triggering of the rule according to the following conditions. You can select multiple conditions.
    • Network—Network properties of the device, such as the device name on the Windows network, or device inclusion in a domain or an IP subnet.

      If case sensitive collation is set for the database that you use for Kaspersky Security Center Cloud Console, keep case when you specify a device DNS name. Otherwise, the auto-tagging rule will not work.

    • Applications—Presence of Network Agent on the device, operating system type, version, and architecture.
    • Virtual machines—Device belongs to a specific type of virtual machine.
    • Active Directory—Presence of the device in an Active Directory organizational unit and membership of the device in an Active Directory group.
    • Applications registry—Presence of applications of different vendors on the device.
  7. Click OK to save the changes.

    If necessary, you can set multiple conditions for a single rule. In this case, the tag will be assigned to a device if it meets at least one condition.

  8. Click Save to save the changes.

The newly created rule is enforced on devices managed by the selected Administration Server. If the settings of a device meet the rule conditions, the device is assigned the tag.

Later, the rule is applied in the following cases:

  • Automatically and periodically, depending on the server workload
  • After you edit the rule
  • When you run the rule manually
  • After the Administration Server detects a change in the settings of a device that meets the rule conditions or the settings of a group that contains such device

You can create multiple tagging rules. A single device can be assigned multiple tags if you have created multiple tagging rules and if the respective conditions of these rules are met simultaneously. You can view the list of all assigned tags in the device properties.

Page top
[Topic 175878]

Running rules for auto-tagging devices

When a rule is run, the tag specified in properties of this rule is assigned to devices that meet conditions specified in properties of the same rule. You can run only active rules.

To run rules for auto-tagging devices:

  1. View rules for tagging devices automatically.
  2. Select check boxes next to active rules that you want to run.
  3. Click the Run rule button.

The selected rules are run.

Page top
[Topic 175974]

Deleting a rule for tagging devices automatically

To delete a rule for tagging devices automatically:

  1. View rules for tagging devices automatically.
  2. Select the check box next to the rule that you want to delete.
  3. Click Delete.
  4. In the window that opens, click Delete again.

The selected rule is deleted. The tag that was specified in properties of this rule is unassigned from all of the devices that it was assigned to.

The unassigned device tag is not deleted. If you want, you can delete it manually.

Page top
[Topic 175976]