Inspection plan settings

更新时间:
复制 MD 格式

This topic describes how to create custom inspection plans in Intelligent Advisor for your business scenarios when the default Well-Architected Multi-dimensional Inspection Plan does not meet your needs.

View an inspection plan

  1. If your account has Resource Directory (RD) enabled and you log on to manage a resource directory or manage a delegated administrator account, you can select the account that you want to inspect. A management account or a delegated administrator account can start or view inspections for member accounts in the same organization. An independent account or a member account can only start or view inspections for the current account. For more information, see Account association.

  2. In the navigation bar, click Inspection Plan Settings to navigate to the Inspection Plan Settings page.

  3. Select the inspection plan that you want to view and click Details. The Basic Information and Resource Scope tabs appear, where you can view the check items and resource scope of the plan.

    • View the basic information on the inspection plan details page.

    • View the resource scope on the inspection plan details page.

      Note: A hyphen (-) in the resource scope field indicates that no resource scope is set and all resources will be inspected.

    • You can filter check items by different categories.

      • Cloud product category

      • Check item

      • Five check item categories: Security Compliance, Performance and Efficiency, Business Stability, Cost Optimization, and Service Limits.

      • Check item source: Intelligent Advisor, Cloud Governance Center, and CloudConfig.

      • Status: Enabled, Disabled, Authorized, or Unauthorized.

        • Check items related to Cloud Monitor are disabled by default because they consume Cloud Monitor API calls. You can enable these check items manually if needed.

        • In addition to Intelligent Advisor, multi-dimensional check items are also sourced from Cloud Governance Center and CloudConfig. If you have not granted authorization to these services, the related check items are displayed as Unauthorized and will not be run.

Create an inspection plan

Overall flow: Basic Information > Select Template > Select Check Items

  1. If your account has Resource Directory (RD) enabled, you can select an account to inspect based on your logon identity. A management account or a delegated administrator account can start or view inspections for member accounts. An independent account or a member account can only run inspections for the current account.

  2. In the navigation bar, click Inspection Plan Settings. On the Inspection Plan Settings page, click Create.

  3. Enter the basic information.

    • Basic Information: Enter a unique Inspection Plan Name (required) and a Description.

    • Resource Scope: Specify whether to Include or Exclude resources. You can only include UIDs. If you leave this parameter empty, all resources are inspected. The conditions are combined using a logical AND.

      • User UID: If you log on as a management account or a delegated administrator account, you can select one or more member accounts. If you log on as a member account or an independent account, the current account is selected by default.

      • Resource ID: The IDs of the resources to inspect.

      • Resource Name: Enter a regular expression for the custom resource name.

      • Resource Region: The region of the resources that you want to inspect.

      • Tag: Inspects resources that have the specified tags.

      • Resource Group: You can inspect resources by a specified resource group. (Note: If you set scope conditions for both User UID and Resource Group, you must configure the Resource Group scope for each UID. UIDs without a configured Resource Group scope are considered to not have a resource group condition and will be filtered out.)

  4. Click Next to go to the Select Template page.

    • If you want to use the check items from an existing plan template, select a template and click Next. If you do not need to use a template, click Next to add new check items.

    • The check items from your selected template are automatically added to the new inspection plan. On this page, you can add or remove check items. If you do not select a template, the check item list is empty, and you must add check items manually.

  5. Click Create. A message indicates that the plan was created successfully. You can then find Multi-dimensional Inspection in the navigation bar and select this plan to run an inspection.

Modify an inspection plan

Ways to open the modification page for an inspection plan

  1. In the navigation bar, select Multi-dimensional Inspection. From the plan drop-down list, select the plan to modify and click the gear icon.

  1. Alternatively, select Inspection Plan Settings from the navigation bar. Find the inspection plan you want to modify and click Details.

Modify basic information or the inspection scope of a plan

  • On the inspection plan details page, click Edit Basic Information in the upper-right corner.

  • On the edit page, you can modify the basic information and the resource scope at the plan level.

    • Resource Scope: You can choose to Include or Exclude resources, but UIDs can only be included. If you leave this section empty, all resources are inspected. The conditions are combined with a logical AND.

      • User UID: If you log on as a management account or a delegated administrator account, you can select one or more member accounts. If you log on as a member account or an independent account, the current account is selected by default.

      • Resource ID: The IDs of the resources to inspect.

      • Resource Name: Enter a regular expression for the resource name.

      • Resource Region: The region of the resources to inspect.

      • Tag: Inspect resources by tag.

      • Resource Group: Inspects resources in the specified resource group. (Note: If you set both the [User UID] and the [Include] [Resource Group] scope conditions, you must configure the [Resource Group] scope for each UID. UIDs that do not have a configured [Resource Group] scope will be filtered out.)

Add check items

  • Click Add Check Item. Select the check items to add and click OK.

    Note: Check items that are already added to this plan are filtered out. Only the check items that can be added under the current filter conditions are displayed.

Remove check items

  • On the inspection plan details page, find the check item to remove and click Remove.

Enable or disable check items

  • To enable a disabled check item, click Enable in the Actions column.

    Note: Check items related to Cloud Monitor are disabled by default because they consume Cloud Monitor API calls. You can enable these check items manually if needed.

  • To disable an enabled check item, click Disable.

Configure the resource scope for a check item

  1. Find the check item whose resource scope you want to modify and click Resource Scope to open the resource scope settings page.

  1. On the Resource Scope Settings page, the inspection scope defaults to All Inspection Resources. To change this, select Partial Resources and click OK.

    Note: The conditions are combined with a logical AND. When you set a partial resource scope for a specific check item, the inspection results are filtered again based on the resource scope set for the plan.

Configure check item parameters

  • For check items that support custom parameter settings, find the relevant check item in the inspection plan and click Parameter Settings.

    image.png

  • On the Parameter Settings page, you can view or modify the configuration thresholds. When you are finished, click OK.

    • For example, for the "RDS Performance Load" check item and its CPU utilization parameter:

      • Time Range: Inspects the last 3 days (up to a maximum of 7 days).

      • Sampling Result Ratio (%): The system collects a result once per minute. More than 80% of the results are greater than the measurement threshold.

      • Greater than Measurement Threshold (%): CPU utilization is greater than 80%.

Resource scope settings

You can set the resource scope for inspections based on different business scenarios. The resource scope can be set in the following ways:

  • Global settings at the inspection plan level.

  • Individual settings at the check item level.

Global settings at the inspection plan level

  1. In the navigation bar, click Inspection Plan Settings to go to the Inspection Plan Settings page.

  2. Select the inspection plan that you want to modify. Click Details, and then click the Resource Scope tab to view the current resource scope.

  3. To modify the resource scope, click Edit Basic Information in the upper-right corner.

  4. On the edit page, you can modify the basic information and the inspection scope.

    Note: The resource scope conditions are combined with a logical AND.

Individual settings at the check item level

  1. In the navigation bar, click Inspection Plan Settings to open the Inspection Plan Settings page.

  2. Select the inspection plan to configure and click Details.

  3. Find the check item that you want to modify and click Resource Scope to open the Resource Scope settings page.

  4. By default, All Inspection Resources is selected on the Resource Scope Settings page. To change the scope, select Partial Resources and click OK.

    Note: The conditions are combined with a logical AND. When you set a partial resource scope for a specific check item, the inspection results are filtered again based on the resource scope set for the plan.