Security Service
Security Service provides security capabilities such as log audit, bastion host, and host security EDR based on an Anheng Tianchi connection. Users can view service status in ZCF, enable, access, upgrade, renew, or unsubscribe from security capabilities as needed, and track related task progress.
The Security Service entry and available operations depend on connection status, SSO configuration, application packages, resource conditions, license authorization, and account permissions. Visible entries and supported operations may vary by environment.
Core Concepts
Before using Security Service, learn the following concepts.
| Concept | Description |
|---|---|
| Security Service | The ZCF entry for enabling and maintaining security capabilities. The current version covers log audit, bastion host, and host security EDR. |
| Log Audit | Collects and audits key operation and security logs for security search and compliance analysis. |
| Bastion Host | Controls operations login, records sessions, and helps intercept high-risk commands. |
| Host Security EDR | Provides threat detection, baseline checks, and exception handling for cloud hosts. |
| Security Service Application Package | A version resource required for deploying or upgrading a security capability. Package status affects enabling, redeployment, and upgrade operations. |
| Security Service Task | An execution record generated by operations such as enabling, redeployment, upgrade, renewal, unsubscription, and resource cleanup. It is used to track the current step, result, and exception cause. |
Access Security Service
Before accessing Security Service, make sure the following conditions are met:
- Anheng Tianchi is connected to ZCF and the connection is normal.
- SSO configuration has been applied to Anheng Tianchi, or the environment has an available unified access configuration.
- The current account has permissions for Security Service.
- You are in the default region.
The Security Service page shows the enabling status, business specification, running health, and recent tasks of log audit, bastion host, and host security EDR. From this page, users can enable, access, or maintain the corresponding security capability.
After entering the page, check security capability status first. For initial enabling, confirm that application packages, service networks, and resource conditions are ready.
View Security Service Status
Security capability cards show the enabling status, business specification, expiration time, instance status, instance health, and recent tasks of log audit, bastion host, and host security EDR. Use this information to decide the next operation.
View and Import Security Service Application Packages
Before importing an application package, prepare the package file that matches the target security capability and version, or prepare a download URL that ZCF can access.
Security service application packages provide the version resources required for enabling or upgrading log audit, bastion host, and host security EDR. Users can check package status before enabling a security capability. If the target version is missing, import the application package from the page entry.
Enable a Security Service
Before enabling a Security Service, make sure the following conditions are met:
- Anheng Tianchi is connected to ZCF and SSO configuration is available.
- The application package required by the target security capability is imported and available.
- Compute, storage, and service network resources are available in the default region.
- Anheng products, specifications, and licenses can be queried normally.
- The current account has permission to enable Security Service.
Users can enable log audit, bastion host, or host security EDR from the Security Service page. The system creates an enabling task based on the selected version, business specification, subscription duration, and resource conditions. After the task is complete, users can access the corresponding security capability.
If enabling fails, check the failed step and cause in the task details. Administrators with required permissions can retry from the failed step or redeploy according to the page prompt.
Access an Enabled Security Service
Before accessing a Security Service, make sure the target capability is enabled, the current account has access permissions, and SSO configuration is available.
After a security capability is enabled, users can access log audit, bastion host, or host security EDR from ZCF. The system provides a controlled access entry based on the current user and service instance.
Handle Security Service Exceptions
Security Service exceptions are usually related to connection status, SSO configuration, application packages, resource quotas, service networks, Security Service provider status, or task execution failures. Check page prompts and task details first, and then retry, redeploy, or contact an administrator as needed.
After the exception is handled, return to the Security Service page and refresh the status to confirm that the capability is available again.
Upgrade, Renew, or Unsubscribe from a Security Service
Before upgrading, renewing, or unsubscribing from a Security Service, make sure the target capability is enabled and the current account has the required operation permission. Before upgrade, also make sure the target application package, business specification, and resource conditions are available.
After a Security Service is enabled, users can upgrade the specification, extend the service period, or unsubscribe from the capability according to business needs. ZCF creates a task for each change operation, and users can track progress and exceptions in the task details.
Note: During unsubscription, do not repeatedly submit mutually exclusive operations such as access, upgrade, renewal, or redeployment. After unsubscription is complete, enable the capability again if it is required later.