Skip to main content

Security Policy Guide 26.x

Label Groups

Label groups streamline policy creation by grouping common labels for efficient rule application. Each Label Groups list page can hold up to 10,000 groups, with individual pages supporting 10,000 members. Utilize filters to locate labels or groups.

Example: Workloads across Dallas, New York, and Washington can be collectively managed by creating a "US" Location label group. This method avoids separate rules for each location.

Displayed label group details include provision status, name, type (e.g., Role, Application), current policy use, last modified timestamp, and modifying user.

Policy Calculation Using Label Groups

Label groups can be nested, so it is essential to understand how they can impact policy.

Note

You cannot assign a label group to a workload - only individual labels can be applied to workloads. Label groups can only be used in policies.

Create a Label Group

Create label groups when you want to combine several labels that share common characteristics into a single label category. After the labels are added to a Label Group, you can use the label group in a rule.

  1. From the PCE web console menu, choose Policy Objects > Label Groups.

  2. On the Label Groups page, click Add.

  3. In the Add Label Group page, choose the label type and enter a name for the label. You cannot create a label group name that already exists, regardless of its alphabetic case. For example, you cannot create a new label group named "WINDOWS" if the label group name "Windows" already exists.

  4. Click Save.

  5. In the Members tab, click Add.Use the dropdown list to find existing labels. You can also enter a label name to create a new label, click Save, then add the new label to the group. You can add as many labels (or label groups) of the same type to the group as desired.

  6. Click OK.

You cannot create a label group name that already exists, regardless of its case. For example, you cannot create a new label group named "WINDOWS" if the label group name "Windows" already exists.