Review Details for a Single Cloud Account
Copy link

The Cloud Account Detail Page is the dedicated page for an individual cloud account.

To review details for a cloud account:

  1. Navigate to Data Connectors > Cloud Accounts and click the cloud account you want to view details for.

Overview
Copy link

Each Cloud Overview page includes high-level status information, including cloud type, name, and account details, harvesting status and permissions, and harvested resources summary. Some cloud types will also have information on the number of harvested resources by type. All of this data refreshes every 2 hours. Additionally, some cloud types have access to a Best Practices & Recommendations section that lists curated Insights reflecting common security issues and high-impact concerns. This list varies by Cloud Service Provider (CSP). For each Insight listed, you can click to view a filtered set of resources based on the selected cloud and specific Insight.

Harvest Info
Copy link

The Harvest Info tab from the overview page of the individual cloud provides details (for example, resource type, region, etc.) from the last known harvest. This is useful in understanding when a particular resource was last harvested, failures and context, the next scheduled harvest, or when a Bot action was last run.

You can manually trigger a harvesting job either through Enqueue Now (in the Action menu) for an individual job/resource type, or by selecting multiple jobs to activate the Enqueue Selected button. Clicking this button will trigger harvesting for multiple jobs.

Settings
Copy link

The Cloud Settings tab allows you to explore the settings for your clouds accounts. Consider the following when interacting with this tab:

  • Permissions - For all of the actions available on this tab, appropriate permissions are required. If you are not able to view certain details or make changes, reach out to your administrator or contact us via the Customer Support Portal .
  • Removing Cloud Accounts - Removing a cloud account from Cloud Security (InsightCloudSec) does not delete the cloud itself from the cloud service provider. Removing a cloud account from Cloud Security (InsightCloudSec) removes the ability to provide you with complete and accurate visibility into your cloud operations.
  • Organization Child Accounts - This page will look slightly different (with certain aspects being locked down) for accounts that are part of a Cloud Organization.

Managing settings
Copy link

You can manage the following settings:

  • Updating the Account information
  • Configuring Billing information (which also including configuration of a billing bucket for AWS or GCP)
  • Updating the EKS Scanner Role associated with the account for Kubernetes Security Guardrails
  • Removing a Cloud Account
  • Assign Harvesting Strategy
  • Setting Custom Properties
    • With appropriate permissions, you can view and add custom properties to your cloud account. These can be used as metadata or to otherwise extend the functionality of your work within Cloud Security (InsightCloudSec).

Configuring a Billing Bucket (AWS only)
Copy link

For AWS accounts, your system administrator can configure the billing bucket for the selected cloud account. Billing information will be pulled from this location periodically. For more information, review AWS Billing Bucket

APIs (GCP only)
Copy link

For GCP Cloud accounts, an additional tab is available. This tab will display all the GCP APIs that Cloud Security (InsightCloudSec) uses with details on their status (Enabled or Disabled). Check out the content we have on Projects for (GCP) for additional details on configuration. From this page, you can also turn on Automatic API Enablement if you want to automatically turn on and harvest from every GCP API that Cloud Security (InsightCloudSec) supports, however this requires you to manually enable the Service Usage API in the GCP Cloud Console. In general, Automatic API Enablement is not recommended because it may reduce performance and increase cost. Additionally, it is best security practice to leave unused APIs turned off.

Compartments (OCI only)
Copy link

The Compartments tab displays any cloud compartments available to an Oracle Cloud Infrastructure account you have added to Cloud Security (InsightCloudSec).