[ Applies to ] StorageGuard 9.x and later / HPE Alletra MP storage systems / Alletra MP REST API
StorageGuard collects configuration data from HPE Alletra MP storage systems by running read-only API calls directly on the storage system. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| System address | The network name or IP address of each HPE storage system. |
| Credentials | A storage system user account, either existing or created for StorageGuard. |
| Role and permissions | Read-only privileges. The service role is recommended; see the role comparison below. Examples of API calls used: GET /api/v3/system, GET /api/v3/users, and GET /api/v3/syslog-servers. |
| Network access | HTTPS connectivity (port 443 by default) from the StorageGuard server to each storage system. |
Create a scan account
The following procedure is a suggested way to create a user named sguard with the service role. You can use any user name.
- Log in to the storage system CLI with an administrator account.
-
Create the user. Replace
<password>with the account password and<domain>with the domain name:createuser -c <password> sguard <domain> service
| Role | What StorageGuard can check |
|---|---|
| service (recommended) | All checks. This role is required to run the read-only controlencryption status and controlsecurity fips status commands, which are essential for security hardening checks. |
| browse | Most checks. Not recommended, because the encryption and FIPS checks can't run. |
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.