Anomaly configuration to enable automatic scanning
Anomaly detection flow can trigger malware scan for those anomalies that have high severity. You need to use the configuration file to do the required settings.
To enable automated scan for images on which the anomaly was detected
- Create the following configuration file:
/usr/openv/var/global/anomaly_detection/anomaly_config.conf
- Add the following contents in the anomaly_config.conf configuration file:
#Use this setting to start malware scan on anomaly detected image automatically.
[AUTOMATED_MALWARE_SCAN_SETTINGS]
ENABLE_AUTOMATED_SCAN=1
# Enable all clients. In this case pool mentioned SCAN_HOST_POOL_NAME will be used for clients not mentioned
# under batch
ENABLE_ALL_CLIENTS=1
SCAN_HOST_POOL_NAME=<scan_host_pool_name> # Default pool name
#Use specific pool for mentioned clients
NUM_CLIENTS_BATCH_SPECIFIED=2
ENABLE_SCAN_ON_SPECIFIC_CLIENT_1=client1,client2
SCAN_HOST_POOL_NAME_1=<scan_host_pool_for_batch_1>
ENABLE_SCAN_ON_SPECIFIC_CLIENT_2=client3,client4
SCAN_HOST_POOL_NAME_2=<scan_host_pool_for_batch_2>
- Ensure that all settings are under [AUTOMATED_MALWARE_SCAN_SETTINGS]. Review the following descriptions of the settings:
ENABLE_AUTOMATED_SCAN=1
Starts malware scan on anomalies with high score.
ENABLE_ALL_CLIENTS=1
Enable all clients for scan. If this value is 0, scanning happens only on the clients that are mentioned under ENABLE_SCAN_ON_SPECIFIC_CLIENT_<Batch_Number>
NUM_CLIENTS_BATCH_SPECIFIED=<batches>
Specifies the number of batches for different scan host pool.
For example, if you want to use a specific scan host pool for a set of clients, use this setting.