Define an application automatically
You can define an application in Illumio Segmentation for the Cloud using Application Discovery Rules. To define an application individually, see Define an application individually.
For an explanation of application definitions and how they relate to deployments, see Deployments and Applications.
Prerequisites
Before you define an application, you must onboard at least one cloud account. Defining a deployment is optional. See Define a Deployment.
Define Applications Automatically
Although Illumio Segmentation for the Cloud has allowed you to define applications individually, you can automatically create multiple applications by defining an Application Discovery Rule. This feature runs in the background so the rule you create automatically defines applications when new resources are added that meet the rule parameters.
Create an Application Discovery Rule
If you have not defined your first application, either individually or with an Application Discovery Rule, use the Application Definitions page to add your first application definition using either method. Click Add Application Definition, select Application Discovery Rule, and click Confirm to begin.
If you have already added an application individually, but not yet with the Application Discovery Rule method, a banner invites you to do so. Click Create to begin.
If you have already created an Application Discovery Rule, navigate to the Application Discovery menu item.
Application Discovery Rule Guidelines
Choose your rule name and clearly name the sort of applications you are automatically defining.
You can add a prefix to the name of all applications discovered with the rule.
The prefix and name may be changed when editing the rule. Other parts of the rule are not editable.
When editing the rule, if the edit does not affect an existing application definition, you do not need to modify or re-approve the application. If the edit affects an existing application definition, then the following apply:
If the change is to only the prefix in the rule, rename the existing application label to reflect the new prefix. You do not need to re-approve application.
If any of the change is to metadata (the type of rule, such as account/subscription, virtual network, etc.), you may need to review and approve new or existing application deployments.
When you save your rule edits, the application approval or re-approval workflows begin. Review and remove any policies associated with application labels that were previously associated with the rule.
The rule's exact behavior may vary depending on the rule type you select.
Cloud Tags: If you choose this rule type, a Cloud Tag Keys dropdown menu appears.
Cloud Accounts: If you choose this rule type, it applies to all the available account/subscription across all accounts and ties an application to each account/subscription with the relevant resources. You can specify the CSPs to which the rule applies. You can have only one rule of this type.
Virtual Networks: If you choose this rule type, it applies to all the available virtual networks across all accounts and ties an application to each virtual network with the relevant resources. You can specify the CSPs to which the rule applies. You can have only one rule of this type.
Subnet: If you choose this rule type, it applies to all the available subnets across all of your accounts, and ties any application to each subnet with the relevant resources. You can specify the CSPs to which the rule applies. You can have only one rule of this type.
Application Discovery Rules cannot be disabled or paused once added. There are two workarounds:
You can delete the rule, which will also delete all application definitions created with the rule.
You can modify individual application definitions for those created with the rule, which decouples the application definition with the rule.
After you create an Application Discovery Rule, you can browse to Discovery Rules > View details to edit it.
Application definitions have contexts for how they were created, viewable on their respective detail pages, either individually or using an Application Discovery Rule.
Note
For any application definitions created with an Application Discovery Rule, the approval process begins as described in View and Approve an Application, unless you click the Auto Approve Setting toggle to ON. Do this if you want Illumio Segmentation for the Cloud to automatically approve all discovered application definitions, as well as any updates made to their deployments and resources. This skips the manual approval process for automatically defined applications. If you click the toggle to OFF, you must approve the discovered application definitions manually. See View and Approve an Application.
Application Label Conventions
Tag-based application labels are generated in the format
Prefix-<TagValue>, e.g. infosec-paymentAccount/Subscription-based application labels are generated in the format
Prefix-<unique account/sub identifier>, e.g. InfoSec-Act123VPC/VNet based-metadata application labels are generated in the format
Prefix-<unique virtual network identifier> InfoSec-VirtualNetwork123Subnet based metadata application labels are generated in the format
Prefix-<unique subnet identifier> InfoSec-Subnet123
Edit an Application Definition
You can update or edit an application you have already defined.
From the Application Discovery > Application Definitions tab, find the application label for which you want to edit the definition.
Click View Details.
Click Edit.
If you change the Auto Approve Setting toggle, you must confirm and save to retain the toggle change.
Delete Application Discovery Rule-Created Application Definitions
When you delete applications that are pending approval, Illumio Segmentation for the Cloud deletes the application definitions.
When you delete approved applications, Illumio Segmentation for the Cloud deletes the application definitions and the rulesets (policies) associated with the application definitions and the application instances. Illumio Segmentation for the Cloud also disassociates any related resources from the application definitions being removed.
Note
Deleting a discovery rule automatically deletes all application definitions associated with the rule.
You can manually delete associated application definitions
Select Application Discovery > Discovery Rules.
The Application Discovery page appears, and the Discovery Rules tab is selected.
For the Application Discovery Rule, select the View Details link in its table row.
The Details page for that rule appears.
In the Discovered Application Definitions section of the Details page, select all the application definitions that you want to delete and click Remove.
Verify that you are deleting the correct applications and click Remove.
Exporting an Application Definition Report
Click Export on the Application Definitions tab.
Edit the report name and select the format.
Click the Scheduling Section toggle to the on position to schedule the export, unless you want to export the report immediately.
Schedule your report, select your recurrence, and time.
Click Save.
Go to the Reports page to download the exported report.
View and Approve an Application
Approve your application. (Each instance of the application in different deployments requires approval.) See View and Approve an Application.
Begin creating the policy for your application.