Software Secure Workload
Activity Configure

Create an Inventory Filter

Create inventory filters to:

  • Create or discover policies specific to subsets of workloads within a scope.

    For example, create a group of API servers within the scope, the servers must be accessible through the API interface. Create policies to allow only the permissible traffic, but block access to all other workloads for that application.

  • Create policies for workloads that exist across many scopes.

    For example, to create a policy that applies to all workloads on the network running a particular operating system, create an inventory filter that spans across multiple or all scopes.


 

To convert an existing cluster to an inventory filter, see Convert a Cluster to an Inventory Filter.

Procedure

1

Navigate to one of the following locations:

  • Choose Organize > Inventory Filters.

  • Navigate to any workspace in a scope for which you want to create an inventory filter and click Manage Policies > Filters > Inventory Filters.

2

Click Create Filter or Add Inventory Filter.

3

Add a name, description, and query that includes all, and only those workloads to include in the filter.

4

Click Show Advanced Options.

5

Specify the scope for the filter.

  • To modify the filter, you must have write access to the specified scope or any of its ancestors.

  • (Depending on other settings in this procedure) The workloads included in the filter.

6

Configure options:

To

Do This

Include workloads that meet the filter query criteria, whether they are members of the scope that is specified in this filter.

Deselect Restrict Query to Ownership Scope

Include only workloads that are members of the scope that is specified in this filter.

Choose Restrict query to ownership scope.

Allow automatic policy discovery to suggest policies specific to the set of workloads defined by this filter.

These workloads must be a subset of the scope that is specified in the filter.

Select Restrict Query to Ownership Scope and Provides a Service External of its Scope.

To use this filter, you must configure external dependencies.

For more information, see Fine-Tune External Dependencies for a Workspace.

7

Click Next.

8

Review the details and click Create.