By adding a primary AWS Account, you can automatically add all the linked AWS Accounts in your organization in the vRealize Network Insight Cloud.
- Firewall Configuration for AWS API Access.
- Create a Primary and Linked Account Policy.
- Create a Role in AWS.
- Create a User in AWS Account.
- Get your Amazon Access Key ID that you created in the AWS console. For more details, see http://docs.aws.amazon.com/general/latest/gr/managing-aws-access-keys.html.
- Get the role Amazon Resource Names (ARN) of the linked AWS account. See, Amazon Resource Names (ARNs) and AWS Service Namespaces
- On the Settings page, click Accounts and Data Sources.
- Click Add Source.
- Under the Public Clouds, click Amazon Web Services.
- In the Add a New AWS Account or Source page, provide the required information.
Option Action Collector VM Select a collector VM from the drop-down menu. Access Key ID Enter your Amazon Access Key ID. Secret Access Key Enter the corresponding Secret Access Key.Note: vRealize Network Insight Cloud takes 15–20 minutes to collect your AWS account data. Web Proxy (Optional) Select a web proxy from the drop-down menu.
- Click Validate.
If the number of VMs discovered exceeds the capacity of the platform or a collector node, or both, the validation fails. You will not be allowed to add a data source until you increase the brick size of the platform or create a cluster. The specified capacity for each brick size with and without flows is as follows:
Brick Size VMs State of Flows Large 6k Active Large 10k Deactivate Medium 3k Active Medium 6k Deactivate
- After validation of your AWS account completes, select the Add Linked Accounts Automatically check box.
- In Role ARN, enter the role Amazon Resource Names of the linked AWS account to trust the primary AWS Account.
- To get deeper insight of your environment, select Enable Flow data collection (Highly Recommended) check box.
- (Optional) To enable regions specific access, select Allow access to specific AWS regions only check box.
- Enter Nickname and Notes for the data source.
- Click Submit.
vRealize Network Insight Cloud validates Role ARN and adds the account.