Security Service

Security Service provides security capabilities such as log audit, bastion host, and host security EDR based on an Anheng Tianchi connection. Users can view service status in ZCF, enable, access, upgrade, renew, or unsubscribe from security capabilities as needed, and track related task progress.

The Security Service entry and available operations depend on connection status, SSO configuration, application packages, resource conditions, license authorization, and account permissions. Visible entries and supported operations may vary by environment.

Core Concepts

Before using Security Service, learn the following concepts.

Concept Description
Security Service The ZCF entry for enabling and maintaining security capabilities. The current version covers log audit, bastion host, and host security EDR.
Log Audit Collects and audits key operation and security logs for security search and compliance analysis.
Bastion Host Controls operations login, records sessions, and helps intercept high-risk commands.
Host Security EDR Provides threat detection, baseline checks, and exception handling for cloud hosts.
Security Service Application Package A version resource required for deploying or upgrading a security capability. Package status affects enabling, redeployment, and upgrade operations.
Security Service Task An execution record generated by operations such as enabling, redeployment, upgrade, renewal, unsubscription, and resource cleanup. It is used to track the current step, result, and exception cause.

Access Security Service

Before accessing Security Service, make sure the following conditions are met:

  • Anheng Tianchi is connected to ZCF and the connection is normal.
  • SSO configuration has been applied to Anheng Tianchi, or the environment has an available unified access configuration.
  • The current account has permissions for Security Service.
  • You are in the default region.

The Security Service page shows the enabling status, business specification, running health, and recent tasks of log audit, bastion host, and host security EDR. From this page, users can enable, access, or maintain the corresponding security capability.

  1. Enter the default region.

  2. In the main menu, go to Security Service.

    If the Security Service entry is not displayed, check the Anheng Tianchi connection, SSO configuration, license authorization, and current account permissions.

  3. Select a tab to view.

    Tab Description
    Security Service View security capability cards, and perform operations such as enable, access, upgrade, renew, unsubscribe, redeploy, or view tasks based on the current status.
    Application Packages View package version, size, status, and last check time. Application packages are used for enabling, redeploying, or upgrading security capabilities.
    Audit View Security Service operation records to trace enabling, changes, and exception handling.

After entering the page, check security capability status first. For initial enabling, confirm that application packages, service networks, and resource conditions are ready.

View Security Service Status

Security capability cards show the enabling status, business specification, expiration time, instance status, instance health, and recent tasks of log audit, bastion host, and host security EDR. Use this information to decide the next operation.

  1. Go to Security Service.

  2. On the Security Service tab, view the target security capability card.

  3. Check the service status and available operations.

    Status Suggested Action
    Not Enabled Prepare the application package, service network, and resource conditions, and then enable the service.
    Processing Open the task details to view the current step and expected impact.
    Enabled Access the security capability, or upgrade, renew, or unsubscribe from it as needed.
    Abnormal or Failed Check the blocked reason or task details, and then retry from the failed step, redeploy, or contact an administrator according to the page prompt.
    Expired Renew the service as needed. If the service is no longer required, unsubscribe from it.
  4. View instance health and recent tasks.

    Instance health helps confirm online status, alarm status, CPU usage, memory usage, and disk usage. Recent tasks help trace enabling, redeployment, upgrade, renewal, unsubscription, or resource cleanup progress.

View and Import Security Service Application Packages

Before importing an application package, prepare the package file that matches the target security capability and version, or prepare a download URL that ZCF can access.

Security service application packages provide the version resources required for enabling or upgrading log audit, bastion host, and host security EDR. Users can check package status before enabling a security capability. If the target version is missing, import the application package from the page entry.

  1. Go to Security Service and open the Application Packages tab.

  2. View the application package list.

    Item Description
    Security Service The security capability to which the package applies, such as log audit, bastion host, or host security EDR.
    Version The package version. Enabling or upgrade operations can use only available versions.
    Status Shows states such as imported, pending, processing, verification failed, or import failed.
    Last Check Shows the latest update time of the package status, which helps determine whether to refresh or import the package again.
  3. To add an application package, select the import entry, and upload a local file or enter a download URL according to the page prompt.

    Parameter Description
    Security Capability Select log audit, bastion host, or host security EDR.
    Version Enter or select the package version. The version is used during enabling or upgrade.
    File or URL Upload a local application package file or enter an accessible download URL.
    Verification Information If required by the page, enter the checksum or confirm package integrity according to the prompt.
  4. Wait until package verification is complete, and confirm that the status meets enabling or upgrade requirements.

  5. If the package status is abnormal, re-upload, download again, or replace the package version according to the page prompt.

Enable a Security Service

Before enabling a Security Service, make sure the following conditions are met:

  • Anheng Tianchi is connected to ZCF and SSO configuration is available.
  • The application package required by the target security capability is imported and available.
  • Compute, storage, and service network resources are available in the default region.
  • Anheng products, specifications, and licenses can be queried normally.
  • The current account has permission to enable Security Service.

Users can enable log audit, bastion host, or host security EDR from the Security Service page. The system creates an enabling task based on the selected version, business specification, subscription duration, and resource conditions. After the task is complete, users can access the corresponding security capability.

  1. Go to Security Service.

  2. Select the security capability to enable and click Enable.

  3. Complete the enabling information.

    Parameter Description
    Security Capability Select log audit, bastion host, or host security EDR.
    Application Package Version Select a package version that matches the target capability. If no version is available, import an available package first.
    Specification Select a specification based on business scale. Specifications differ by capability, such as log source count, asset count, concurrency, or host security quota.
    Subscription Duration Select the service duration. After expiration, renew or enable the service again as needed.
    Service Network Select the service network used to deploy the Security Service instance. Make sure the network meets access and integration requirements.
  4. Review the resource plan and validation results.

    The resource plan usually includes CPU, memory, system disk, data disk, and network information. Make sure resources, quotas, application packages, and external services meet the requirements shown on the page.

  5. Submit the enabling task.

  6. Open the task details to view the progress.

    Task details show the progress of key validation, resource preparation, order creation, deployment, and instance synchronization. After the task is complete, return to Security Service and access the corresponding security capability.

If enabling fails, check the failed step and cause in the task details. Administrators with required permissions can retry from the failed step or redeploy according to the page prompt.

Access an Enabled Security Service

Before accessing a Security Service, make sure the target capability is enabled, the current account has access permissions, and SSO configuration is available.

After a security capability is enabled, users can access log audit, bastion host, or host security EDR from ZCF. The system provides a controlled access entry based on the current user and service instance.

  1. Go to Security Service.

  2. Find the target security capability card.

  3. Click Access Service.

  4. Use the security capability on the opened page.

    If the browser blocks the new window, allow pop-ups and try again. If access still fails, check the page prompt, SSO configuration, account permissions, and service instance status.

Handle Security Service Exceptions

Security Service exceptions are usually related to connection status, SSO configuration, application packages, resource quotas, service networks, Security Service provider status, or task execution failures. Check page prompts and task details first, and then retry, redeploy, or contact an administrator as needed.

  1. Go to Security Service.

  2. Check the status, blocked reason, and recent task on the target security capability card.

  3. If a failed task exists, click View Task.

  4. In the task details, check the failed step, error source, and error summary.

    Exception Source Handling Direction
    Application Package Make sure the target package version is imported and verified.
    Resources or Network Make sure compute, storage, quotas, and service networks in the default region meet deployment requirements.
    SSO Make sure SSO configuration has been applied to Anheng Tianchi and the current account has access permissions.
    Security Service Provider Make sure Anheng products, specifications, licenses, and instance status can be queried normally.
  5. According to the page prompt, select Retry from Failed Step, Redeploy, or contact an administrator.

After the exception is handled, return to the Security Service page and refresh the status to confirm that the capability is available again.

Upgrade, Renew, or Unsubscribe from a Security Service

Before upgrading, renewing, or unsubscribing from a Security Service, make sure the target capability is enabled and the current account has the required operation permission. Before upgrade, also make sure the target application package, business specification, and resource conditions are available.

After a Security Service is enabled, users can upgrade the specification, extend the service period, or unsubscribe from the capability according to business needs. ZCF creates a task for each change operation, and users can track progress and exceptions in the task details.

  1. Go to Security Service.

  2. Select the target security capability and confirm its current service status.

  3. Based on the current status, select Upgrade, Renew, or Unsubscribe.

  4. Confirm the change and its impact.

    Operation Check Item
    Upgrade Confirm the target version, application package status, business specification, resource plan, and upgrade impact.
    Renew Confirm the renewal duration, current expiration time, and service period after renewal.
    Unsubscribe Confirm that the security capability cannot be used after unsubscription, and understand the impact on related resources and data.
  5. Submit the task.

  6. Open the task details to view progress.

    Upgrade, renewal, and unsubscription tasks show the progress of condition validation, order processing, resource adjustment, instance synchronization, or resource cleanup. If a task fails, check the failed step and error source first, and then retry or contact an administrator according to the page prompt.

During unsubscription, do not repeatedly submit mutually exclusive operations such as access, upgrade, renewal, or redeployment. After unsubscription is complete, enable the capability again if it is required later.

Product Manual | ZStack Cloud Foundation | ZStack Resource Center