[ Applies to ] StorageGuard 9.x and later / Commvault CommCell environments / CommServe
StorageGuard collects configuration data from Commvault by opening an HTTPS connection to the Commvault management server, and running read-only REST API calls. This article describes the requirements and two ways to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| Proxy address | The network name or IP address of the Commvault management server (CommServe or associated API/Web Server). |
| Credentials | A user name and password. See Create a scan account. |
| Role and permissions | The account needs the View role. Examples of read-only REST API endpoints used: CommCell/keyManagementServers, CommServ/SNMPV3Configuration, V4/Snmp, and V4/SyslogServer/Status. |
| Network access | HTTPS connectivity (port 443) from the StorageGuard server to the Commvault management server. |
Create a scan account
Use one of the following suggested methods:
| Option | What StorageGuard can collect | When to use it |
|---|---|---|
| Option 1: Read-only user | All configuration data except SNMP and Audit Trail settings. | You want the minimum permissions. |
| Option 2: User with elevated rights | All configuration data, including SNMP and Audit Trail settings, for a comprehensive risk analysis. | Recommended, but optional. |
Note: Reading SNMP and Audit Trail settings through the API requires elevated rights, even though the calls are read-only. Whichever option you choose, StorageGuard runs only read-only APIs and commands.
Option 1: Read-only user
- Sign in to the Commvault Web UI.
- In the navigation bar, search for security.
- Click Users, and then click Add user, to the left of the search bar at the top right of the page.
- Select Single user, and then Local user. Fill in the form, and click Add.
- Click the new user, and then click Associated entities > Add association.
- For Entity type, select Role, and then select View. Click Add, and then click Save.
Option 2: User with elevated rights (optional)
This option creates a custom role that adds Administrative Management to View, and assigns it to the user.
- Sign in to the Commvault Web UI.
- In the navigation bar, search for security.
- Click Roles, and then click Add role.
- Enter a role name. Under Permissions, search for global, and select View and Administrative Management. Select Visible to all, and then click Add.
- Click Users, and then click Add user, to the left of the search bar at the top right of the page.
- Select Single user, and then Local user. Fill in the form, and click Add.
- Click the new user, and then click Associated entities > Add association.
- For Entity type, select CommCell, and enter the CommCell name. Select the custom role you created in step 4, click Add, and then click Save.
- Add a second association: for Entity type, select Role, and select the same custom role. Click Add, and then click Save.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.