Configuring the Cloud Volumes ONTAP and Amazon FSx for NetApp ONTAP collector
Workload Security uses data collectors to collect file and user access data from devices.
Cloud Volumes ONTAP Storage Configuration
See the OnCommand Cloud Volumes ONTAP Documentation to configure a single-node / HA AWS instance to host the Workload Security Agent:
https://docs.netapp.com/us-en/cloud-manager-cloud-volumes-ontap/index.html
After the configuration is complete, follow the steps to setup your SVM:
https://docs.netapp.com/us-en/cloudinsights/task_add_collector_svm.html
Supported Platforms
-
Cloud Volumes ONTAP, supported in all the available cloud service providers wherever available. For example: Amazon, Azure, Google Cloud.
-
ONTAP Amazon FSx
Agent Machine Configuration
The agent machine must be configured in the respective subnets of the cloud Service providers. Read more about network access in the [Agent Requirements].
Below are the steps for Agent installation in AWS. Equivalent steps, as applicable to the cloud service provider, can be followed in Azure or Google Cloud for the installation.
In AWS, use the following steps to configure the machine to be used as a Workload Security Agent:
Use the following steps to configure the machine to be used as a Workload Security Agent:
-
Log in to the AWS console and navigate to EC2-Instances page and select Launch instance.
-
Select a RHEL or CentOS AMI with the appropriate version as mentioned in this page:
https://docs.netapp.com/us-en/cloudinsights/concept_cs_agent_requirements.html -
Select the VPC and Subnet that the Cloud ONTAP instance resides in.
-
Select t2.xlarge (4 vcpus and 16 GB RAM) as allocated resources.
-
Create the EC2 instance.
-
-
Install the required Linux packages using the YUM package manager:
-
Install wget and unzip native Linux packages.
-
Install the Workload Security Agent
-
Log in as Administrator or Account Owner to your Data Infrastructure Insights environment.
-
Navigate to Workload Security Collectors and click the Agents tab.
-
Click +Agent and specify RHEL as the target platform.
-
Copy the Agent Installation command.
-
Paste the Agent Installation command into the RHEL EC2 instance you are logged in to.
This installs the Workload Security agent, providing all of the Agent Prerequisites are met.
For detailed steps please refer to this link:
https://docs.netapp.com/us-en/cloudinsights/task_cs_add_agent.html#steps-to-install-agent
Troubleshooting
Known problems and their resolutions are described in the following table.
Problem |
Resolution |
“Workload Security: Failed to determine ONTAP type for Amazon FxSN data collector” error is shown by the Data Collector. |
Solve this issue by adding fsxadmin LIF network segment to agent's security rule. |