SSGP4E_3.x - Documentation Index
Table of Contents
Welcome
Guardium Data Security Center overview
Release notes
What's new
Guardium Data Security Center 3.8.0 Release Notes
IBM Guardium Data Security Center 3.8.1 Release Notes
IBM Guardium Data Security Center 3.8.2 Release Notes
IBM Guardium Data Security Center 3.8.3 Release Notes
IBM Guardium Data Security Center 3.8.4 Release Notes
IBM Guardium Data Security Center 3.8.5 Release Notes
IBM Guardium Data Security Center 3.8.6 Release Notes
IBM Guardium Data Security Center 3.8.7 Release Notes
IBM Guardium Data Security Center 3.8.8 Release Notes
IBM Guardium Data Security Center 3.8.9 Release Notes
IBM Guardium Data Security Center 3.8.10 Release Notes
Guardium Data Security Center 3.7.0 Release Notes
IBM Guardium Data Security Center 3.7.1 Release Notes
IBM Guardium Data Security Center 3.7.2 Release Notes
Guardium Data Security Center 3.6.0 Release Notes
IBM Guardium Data Security Center 3.6.1 Release Notes
IBM Guardium Data Security Center 3.6.2 Release Notes
IBM Guardium Data Security Center 3.6.3 Release Notes
Considerations for GDPR readiness
Data source platform streaming support
Planning
Architecture
Operators
Supported project (namespace) configurations
Installation roles and personas
Guardium Data Security Center license guide
Guardium Data Security Center asset guidance
Storage considerations
System requirements and prerequisites
Guardium Data Security Center system requirements and prerequisites
Guardium Data Security Center CLI utility system requirements
Operator and operand versions
Securing your environment and data
Basic security features
Custom security context constraints for services
API keys
Enabling FIPS
Securing communication ports
Auditing Guardium Data Security Center
Hardware cluster requirements
Validated storage options
Port requirements
Domain name and TLS certificates
Installing
Prepare for installing IBM Guardium Data Security Center
Preparing to install an external Db2 database
Downloading the Guardium Data Security Center CASE file and set up your environment for dependencies
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Online and offline/air gap installation of Guardium Data Security Center by using automated (all-in-one) installation script
Configuration file parameters for all-in-one installation
Manually installing Guardium Data Security Center online with an embedded Db2u
Creating a Guardium Data Security Center instance by using a custom resource (CR)
Manually installing Guardium Data Security Center online with an external Db2 cluster
Manually installing Guardium Data Security Center offline
Creating a Guardium Data Security Center instance by using a custom resource (CR)
Manually installing on IBM Cloud with ibmc-file-gold-gid storage
Automated installing on IBM Cloud classic infrastructure
Creating a Red Hat OpenShift cluster
Configuring file storage on IBM Cloud
Setting up your environment
Editing the values configuration file
Running the all-in-one-script
Verifying the installation
Manually installing on IBM Cloud classic with ODF storage
Creating an OpenShift cluster
Installing Red Hat OpenShift Container Storage
Logging in to the Red Hat OpenShift cluster
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Automated installing on Amazon Web Services (AWS)
Automated installing on IBM Cloud Virtual Private Cloud (VPC)
Creating a Red Hat OpenShift cluster
Setting up your environment
Editing the values configuration file
Running the all-in-one-script
Verifying the installation
Manually installing on IBM Cloud Virtual Private Cloud (VPC)
Creating a Red Hat OpenShift cluster
Logging in to the Red Hat OpenShift cluster
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Manually installing on Amazon Web Services (AWS) with ODF storage
Automated installing on Azure
Creating the Red Hat OpenShift cluster on Azure
Installing Openshift Data Foundation (previously OpenShift Container Storage) storage class
Editing the values.conf file to install IBM Common Services and Guardium Data Security Center
Running the all-in-one script
Verifying the installation
Manually installing on ARO
Verifying roles and tenant subscriptions
Setting up the bastion server
Preparing your Azure account for Azure OpenShift
Obtaining a Red Hat pull secret
Creating a virtual network with two empty subnets
Creating the cluster
Connecting to the cluster
Installing the OpenShift command-line interface (CLI)
Connecting to OpenShift by using the CLI
Installing Openshift Data Foundation (previously OpenShift Container Storage) storage class
Logging in to the cluster
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Uninstalling the Guardium Data Security Center instance
Deleting the cluster
Manually installing on Azure
Verifying roles and tenant subscriptions
Set up the bastion server
Installing OpenShift command line interface (CLI)
Downloading Red Hat pull secret
Creating SSH key for OpenShift Container Platform machine access
Logging in to the Azure CLI
Creating a service principal
Granting extra permissions to the service principal
Logging in to the Azure user interface and verify the creation of the service principal
Optional: Creating a Pseudo-Public DNS (PPDN) for Azure
Creating an OpenShift Container Platform (OCP) installation directory and file
Adjusting the installation file to your Guardium Data Security Center requirements
Installing the OpenShift Container Platform (OCP) cluster
Monitoring DNS to get the new CNAME record
Extracting the IP address for the Public CNAME and add it to /etc/hosts
Waiting for cluster deployment
Adding cluster application name translation (for Pseudo Public PDNS)
Adding the record to /etc/hosts on the bastion server
Adding the record to the hosts file on your workstation (for web user interface access)
Verifying OCP deployment
Logging in to the OpenShift user interface
Verifying the cluster API address
Adding default route to image registry
Installing Openshift Data Foundation (previously OpenShift Container Storage) storage class
Logging in to the cluster
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Uninstalling the Guardium Data Security Center instance
Installing on Google Cloud Platform cluster
Installing the Google Cloud CLI
Installing Red Hat OpenShift on GCP
Generating the SSH key
Downloading the service account key
Installing the Red Hat OpenShift GCP cluster
Installing the command-line tool
Installing the Red Hat OpenShift Container Storage
Installing IBM Cloud Pak foundational services on Guardium Data Security Center
Installing Guardium Data Security Center
Validating the installation
Installing on a set of nodes within a namespace
Red Hat OpenShift service on Amazon Web Services (ROSA)
Installing the Guardium Data Security Center command-line interface utility
Azure Red Hat OpenShift (ARO)
IBM Cloud Classic ROKS
IBM Cloud VPC ROKS
OpenShift Dedicated (OSD) on Google Cloud Platform (GCP)
Red Hat OpenShift service on Amazon Web Services (ROSA)
Self-managed Azure IAAS
Self-managed Google Cloud Platform (GCP) IAAS
Preparing to patch or upgrade Guardium Data Security Center
Upgrading Guardium Data Security Center
Upgrading to Guardium Data Security Center version 3.6.0
Downloading the CASE bundle
Upgrading IBM Common Services
Upgrading Guardium Data Security Center manually
Upgrading Guardium Data Security Center by using the all-in-one script
Upgrading Guardium Data Security Center by using the all-in-one script in an air-gaped environment
Upgrading to Guardium Data Security Center version 3.7.0
Downloading the CASE bundle
Upgrading IBM Common Services
Upgrading Guardium Data Security Center manually
Upgrading Guardium Data Security Center by using the all-in-one script
Upgrading Guardium Data Security Center by using the all-in-one script in an air-gapped environment
Upgrading to Guardium Data Security Center version 3.8.0
Downloading the CASE bundle
Upgrading IBM Common Services
Upgrading Guardium Data Security Center manually
Upgrading Guardium Data Security Center by using the all-in-one script
Upgrading Guardium Data Security Center by using the all-in-one script in an air-gapped environment
Patching Guardium Data Security Center
Configuring Prometheus
Manually shutting down Guardium Data Security Center
Manually restarting Guardium Data Security Center
Automatically shutting down and restarting Guardium Data Security Center
Verifying that the Kafka system is drained
Replacing the ingress certificate
Creating a CA-signed certificate
Guardium Data Security Center logging
Uninstalling the Guardium Data Security Center instance
Getting started
Setting up JDBC for user management
Installation of SAML-based authentication
Retrieving login credentials for foundational services
Configuring SAML SSO connection
Logging into Guardium Data Security Center
Creating and using additional tenants after installing Guardium Data Security Center
Getting started with Guardium Quantum Safe
Configuring
Setting up connections
Connecting to Amazon Web Services (AWS) by discovering streams
Connecting to Amazon Web Services (AWS) by manually adding a stream
Connecting to Azure Event Hubs
Configuring LDAP connections
Connecting to data sources by using the universal connector
Available plug-ins and data sources
Connecting to data source by using Universal Connector
Universal Connectors FAQs
Managing activity monitoring connections
Configuring monitoring policies
Creating policy rule actions
Alerting rule actions
Logging rule actions
Creating a custom policy
Creating a policy from a template
Importing policies from Guardium Data Protection
Setting up a data compliance program
California Consumer Privacy Act (CCPA) compliance
General Data Protection Regulation (GDPR)
Sarbanes-Oxley (SOX) Act
Health Insurance Portability and Accountability Act (HIPAA)
Payment Card Industry Data Security Standard (PCI DSS)
Using workflows to schedule jobs and respond to events
Creating a workflow
Creating investigation links
Creating response templates
Creating distribution rules for workflows
Managing groups
Working with and modifying an individual group
Importing group members from a CSV file
Importing group members from LDAP
LDAP group member import filter options
Adding members to groups from within a report
Adding groups
Importing groups from Guardium Data Protection
Creating your own group
Creating a tuple group
Creating new groups from existing ones
Saving groups to CSV file
Using predefined groups
Enabling the Risk Event process
Configuring the Risk Events module
Configuring Risk Events settings
Configuring Risk Event Leads
Integrating independent applications or protocols
Configuring an SFTP integration
Configuring SMB/SAMBA integration
Configuring SMTP for email notifications
Slack configuration
Configuring an SNMP trap
Configuring syslog alerts
Configuring Webhook alerts
Configuring a secret server to access PAM (Privileged Access Management) data
IBM Cloud Pak for Security Cases ticketing configuration
IBM Security QRadar SOAR ticketing configuration
ServiceNow ticketing configuration
Jira ticketing configuration
Configuring Microsoft Teams notifications
Connecting to Guardium Data Protection systems
Connecting to Guardium Data Protection with the direct-to-Guardium Data Security Center communication protocol
Connect to Guardium Data Protection with the legacy communication protocol
Adjusting Guardium central manager and OpenShift Container Platform settings for data mart streaming
Installing the Guardium Data Security Center policy to Guardium Central Manager
Customizing the Guardium connector IP address and port
Export data from Guardium Data Protection systems
Guardium Data Protection data marts
Configuring IBM Guardium Discover and Classify (1touch.io Inventa) integration
Configuring IBM Guardium Big Data Intelligence (GBDI) integration
Exporting data from GBDI
Importing data into Guardium Data Security Center
Creating an inbound API integration
Creating a ticket
Obtaining an SSL certificate
Guardium Quantum Safe
Working with data sets
Creating a custom data import
Working with variants
Creating a variant from the reports page
Creating a variant from the Variant administration page
Administering
Managing tenant settings
Managing users
Viewing user activity
Managing roles
Predefined roles, pages, and permissions
Managing profile settings
Backing up with an embedded Db2u
Restoring a backup with an embedded Db2u
Backing up with an external Db2
Restoring a backup with an external Db2
Using the Guardium Data Security Center API
Creating API keys
Accessing APIs and making API key requests
Replacing API keys using master key rotation
Swagger API 3.6.x
Analyzing collected data and strengthening your data security
Notifications
Dashboards
Creating a custom dashboard
Creating a dashboard from a template
Filtering report cards in dashboards
Using active queries
Using reports
Creating a custom report
Creating a custom report by copying an existing report
Creating a custom report
Filtering the list of reports
Working with a single report
Filtering an individual report
Joining report data with custom data
Predefined reports, tags, and data points
Visualizing the data in a report
Exporting cryptographic reports
Working with tasks
Addressing policy and regulation compliance
Managing asset inventory
Investigating assets and their risk attributes
Asset attributes and overview information
Managing tags
Creating auto-tagging rules
Asset merging and splitting
Merging assets
Splitting assets
Reports and workflows for assets
Risk events
Risk event categories
Viewing and managing Risk Events
Risk events on the overview dashboard
Checking the Risk Events list
Managing a Risk Event
Responding to a Risk Event
Providing feedback
Identifying outliers in server and user behavior
Feature flag for outliers
Parameters for outliers
Viewing Outliers from a collector or aggregator
Monitoring data mart ingestion activity
Monitoring connector and data flow status for Guardium Data Security Center
guardcenter-cli command reference
health
airgap
certs
cluster
kube-version
network-connectivity
network-performance
nodes
operands
operators
registry
runcommand
security-context
storage-performance
storageclass-validation
version
manage
install
all
cluster
guardcenter
Guardium Quantum Safe
System requirements and prerequisites
Sizing guidance
Setting up PostgreSQL
Installing a metrics server in Kubernetes
Setting up a Horizontal Pod Autoscalar
Accessing services over HTTPS using trusted certificates from a certificate authority
Accessing services over HTTPS using self-signed certificates
Quick Start Guide
Known issues
Installing Guardium Quantum Safe
Configuring
Configuration to secure and manage PostgreSQL schemas
Configuring a helper function role to manage PostgreSQL database schemas
Configuring business intelligence tools securely
Configuring Keycloak
Configuring Prometheus with node exporter on Kubernetes
Configuring Perses on Kubernetes
Configuring NooBaa on Kubernetes
Configuring a consolidated log aggregator
Row-Level Access Control (RLAC)
Kubernetes ingress controller with NodePort and Network Load Balancer
Configuring the API
Obtaining a Secure Sockets Layer (SSL) protocol certificate
Administering data
Data ingestion
Built-in plug-in details
Creating custom plug-ins
Creating POJO-based plug-in
Creating a YAML-based plug-in
Registering custom-built plug-ins
Creating and running jobs
Troubleshooting and rerunning failed jobs
Data ingestion APIs
Internal APIs
External APIs
Utility scripts
Domain objects
Creating a dataset
Verifying custom domain metadata and integrity
Managing users
Users
Roles
Integrations
Configuring the Secure File Transfer Protocol (SFTP)
Configuring the Simple Mail Transfer Protocol (SMTP)
Configuring the ServiceNow ticketing tool
Configuring the Jira ticketing tool
Managing policies
Creating a policy
Dashboards and reports
Dashboards
Reports
Viewing audit logs
Troubleshooting problems
Techniques for troubleshooting problems
Troubleshooting with the cpctl utility
Collecting mustgather information for troubleshooting
Downloading support scripts
Troubleshooting mini-snif
Regenerating certificates
Troubleshooting storage limit errors
Platform troubleshooting assistance
Platform-level mustgather
Using the Cloud Pak Healthcheck service
Problems and solutions
Resetting your compliance journey
Reports
Error when running public API if limit is greater than 400
Installation and environment setup
CBC ciphers and SSH vulnerabilities
Db2 client communication issues
Db2 errors for reports and risk services
Db2 pod stuck in pending state
Existing universal connector certificate does not work in a restored environment
Existing data mart pull configuration does not work in a restored environment
Guardium Data Security Center deployment with an external Db2 cluster fails to complete
Guardium Data Security Center failed to install or upgrade with the warning 'clusterserviceversion is not referenced by a subscription'
Guardium Data Security Center upgrade becomes stuck because CSV does not update
Guardium Data Security Center upgrade becomes stuck with MongoDBCommunity error
Kafka pods in CrashLoop when storage size is not large enough
Missing cp-serviceability image in air-gapped environments
Missing MongoDB image results in upgrade and installation failure
MongoDB MongoBleed vulnerability
MongoDB warning in pre-upgrade validation script
NooBaa database PVC storage keeps growing: Reclaim space with VACUUM FULL
Secure Shell (SSH) service error when deploying on Amazon Web Services (AWS)
Troubleshooting Db2 filesystem pods
Troubleshooting Risk Events