[ Applies to ] StorageGuard 9.x and later / Cohesity DataPlatform systems / REST API and CLI
StorageGuard collects configuration data from Cohesity DataPlatform by opening HTTPS and SSH connections to the DataPlatform system, and running read-only REST API calls and CLI commands. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| System address | The network name or IP address of each Cohesity DataPlatform system. |
| Credentials | A user name and password for each DataPlatform system. StorageGuard uses the same credentials for REST API and SSH connections. |
| Role and permissions | The account needs the VIEW role. Examples of REST API endpoints used: SyslogServer and ldapProvider. Example of CLI commands used: cluster get-info. |
| Network access | HTTPS (port 443) and SSH (port 22) connectivity from the StorageGuard server to each DataPlatform system. |
Note: Enter the user name with its domain, for example
DOMAINNAME@user. StorageGuard ignores the domain when it opens the SSH connection.Create a scan account
The following procedure is a suggested way to create a user with the VIEW role.
- Log in to the DataPlatform system CLI with an administrative account.
-
Create the user. Replace
<username>and<password>with the account credentials:user create user-name=<username> password=<password> roles=VIEW - Repeat these steps on each DataPlatform system that StorageGuard scans.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.