Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove ArcFull flavor directory and files #356

Closed
wants to merge 17 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file modified docs/azure_jumpstart_arcbox/DataOps/arch_dataops.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/azure_jumpstart_arcbox/DevOps/arch_devops.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
658 changes: 0 additions & 658 deletions docs/azure_jumpstart_arcbox/Full/_index.md

This file was deleted.

Binary file removed docs/azure_jumpstart_arcbox/Full/activity1.png
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/arcbox_complete.png
Binary file not shown.
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/arch_capi.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/arch_full.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation1.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation2.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation3.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation4.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/automation5.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/az_login_error.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azdatastudio.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azdatausage.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azdelete.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azdeploy.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azgroupcreate.png
Binary file not shown.
Binary file removed docs/azure_jumpstart_arcbox/Full/azvmlistusage.png
Binary file not shown.
Binary file not shown.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/cat_command.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/clientscript.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/dataservices.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/dataservices2.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/deploymentflow.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/hypervterminal.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/k8s.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/kubectx.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/list_skus.png
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/login_motd.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/nsg_add_rule.png
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/parameters.png
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/portaldelete.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/portaldeploy.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/rdp_connect.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/rdp_via_az_cli.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/rg_arc.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/servers.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/ssh_example.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/unifiedops.png
Diff not rendered.
Binary file removed docs/azure_jumpstart_arcbox/Full/workbook.png
Diff not rendered.
394 changes: 299 additions & 95 deletions docs/azure_jumpstart_arcbox/ITPro/_index.md

Large diffs are not rendered by default.

Binary file modified docs/azure_jumpstart_arcbox/ITPro/arcbox_complete.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/arch_itpro.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/automation.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/deploymentflow.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/parameters_itpro_bicep.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/rdp_via_az_cli.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/rg_arc.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/ssh_via_az_cli_01.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/troubleshoot_logs.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/unifiedops.png
Binary file modified docs/azure_jumpstart_arcbox/ITPro/workbook.png
134 changes: 27 additions & 107 deletions docs/azure_jumpstart_arcbox/workbook/flavors/ITPro/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,154 +4,74 @@ weight: 99
toc_hide: true
---

# Jumpstart ArcBox for IT Pros - Azure Monitor Workbook
# Jumpstart ArcBox for IT Pros - Azure Monitor Workbooks

ArcBox for IT Pros is a special "flavor" of ArcBox that is intended for users who want to experience Azure Arc-enabled servers capabilities in a sandbox environment. This document provides specific guidance on the included ArcBox [Azure Monitor Workbook](https://learn.microsoft.com/azure/azure-monitor/visualize/workbooks-overview). Please refer to the main [ArcBox documentation](/azure_jumpstart_arcbox/) for information on deploying and using ArcBox.

As part of ArcBox for IT Pros, an Azure Monitor workbook is deployed to provide a single pane of glass for monitoring and reporting on ArcBox resources. Using Azure's management and operations tools in hybrid, multi-cloud and edge deployments provides the consistency needed to manage each environment through a common set of governance and operations management practices. The Azure Monitor workbook acts as a flexible canvas for data analysis and visualization in the Azure portal, gathering information from several data sources from across ArcBox and combining them into an integrated interactive experience.
As part of ArcBox for IT Pros, two Azure Monitor workbooks is deployed to provide a single pane of glass for monitoring and reporting on ArcBox resources. Using Azure's management and operations tools in hybrid, multi-cloud and edge deployments provides the consistency needed to manage each environment through a common set of governance and operations management practices. The Azure Monitor workbooks acts as a flexible canvas for data analysis and visualization in the Azure portal, gathering information from several data sources from across ArcBox and combining them into an integrated interactive experience.

> **Note:** Due to the number of Azure resources included in a single ArcBox deployment and the data ingestion and analysis required, it is expected that metrics and telemetry for the workbook can take several hours to be fully available.

## Access the ArcBox for IT Pros workbook
## Access the ArcBox for IT Pros workbooks

The Jumpstart ArcBox workbook is automatically deployed for you as part of ArcBox's advanced automation. To access the Jumpstart ArcBox workbook use the Azure portal to follow the next steps.

- From the ArcBox resource group, select the Azure Workbook, then click "Open Workbook"

![Workbook Gallery](./azure_workbook.png)

Click on the workbook you want to open and select _Open Workbook_:

![Workbook Gallery](./open_workbook.png)

- The Jumpstart ArcBox for IT Pros Workbook will be displayed.
- The selected Jumpstart ArcBox for IT Pros Workbook will be displayed.

![ArcBox for IT Pros workbook overview](./workbook_overview.png)
**Inventory workbook**

## ArcBox for IT Pros Workbook capabilities
![ArcBox for IT Pros workbook overview](./workbook_inventory.png)

**Performance workbook**

The ArcBox for IT Pros Workbook is a single report that combines data from different sources and services, providing a unified view across resources, enabling richer data and insights for unified operations.
![ArcBox for IT Pros workbook overview](./workbook_performance.png)

The Workbook is organized into several tabs that provide easier navigation and separation of concerns.
## ArcBox for IT Pros Workbook capabilities

![Tab Menu](./tab_menu.png)
The ArcBox for IT Pros Workbooks combines data from different sources and services, providing a unified view across resources, enabling richer data and insights for unified operations.

### Inventory

By using Azure Arc, your on-premises and multi-cloud resources become visible through Azure Resource Manager. Therefore, you can use tools such as Azure Resource Graph as a way to explore your inventory at scale. Your Azure Resource Graph queries can now include Azure Arc-enabled resources with filtering, using tags, or tracking changes.

The "Inventory" tab in the ArcBox for IT Pros Workbook has three sections:

- _parameters_ - use the drop-down menu to select your subscription and resource group, you also get the option to filter the report by resource type.
Overall status and policy compliance:

![Inventory Parameters](./inventory_parameters.png)
![Inventory](./inventory_01.png)

- _Resource Count by Type_ - this visualization shows the number of resources by type within a resource group, these grouping will be automatically refreshed if the parameters section is changed.
Update status:

![Inventory Resource by type](./inventory_count_by_type.png)
![Update status](./inventory_02.png)

- _Resource List_ - this table shows a list of resources in the resource group provided in the parameters section. This is an interactive list, therefore you can click on any resource or tag for additional information.
Active alerts in Defender for Cloud:

![Inventory Resource List](./inventory_resource_list.png)
![Update status](./inventory_03.png)

### Monitoring

Enabling a resource in Azure Arc gives you the ability to perform configuration management and monitoring tasks on those services as if they were first-class citizens in Azure. You are able to monitor your connected machine guest operating system performance at the scope of the resource with VM insights. In ArcBox for IT Pros the Azure Arc-enabled servers have been onboarded onto Azure Monitor.

The "Monitoring" tab of the Jumpstart Workbook shows metrics and alerts for ArcBox for IT Pros resources organized in three sections:

- _Alert Summary_ - Shows an overview of alerts organized by severity and status. You can use the drop-down menus to apply filters to the report. The following filters are available:
- Subscription: select one or multiple subscriptions in your environment to show available alerts.
- Resource Group: select one or more resource groups in your environment to show available alerts.
- Resource Type: select one or multiple resource types to show its alerts.
- Resources: select individual resources by name to visualize their alerts.
- Time Range: provide a time range in which the alert has been created.
- State: choose the alert type between New, Acknowledged, or Closed.

![Monitoring Alert Summary](./monitoring_alert_summary.png)

- _Azure Arc-enabled servers_ - Shows metrics for CPU and memory usage on the Azure Arc-enabled servers. Use the parameters section to select the Azure Arc-enabled server as well as a time range to visualize the data.

![Monitoring Azure Arc-enabled server Metrics](./monitoring_arc_servers.png)

### Microsoft Defender for Cloud

Microsoft Defender for Cloud can monitor the security posture of your hybrid and multi-cloud deployments that have been onboarded onto Azure Arc. Once those deployments are registered in Azure, you can take care of the security baseline and audit, apply, or automate requirements from recommended security controls as well as identify and provide mitigation guidance for security-related business risks.

The "Security" tab of the Jumpstart Workbook shows insights from Microsoft Defender for Cloud assessments. To be able to use this report, you will need to configure "continuous export" capability to export Microsoft Defender for Cloud's data to ArcBox's Log Analytics workspace:

- From Microsoft Defender for Cloud's sidebar, select Environment Settings.

![Microsoft Defender for Cloud Configuration](./security_center_config_1.png)

- Select the specific subscription for which you want to configure the data export.

![Microsoft Defender for Cloud Configuration](./security_center_config_2.png)

- From the sidebar of the settings page for that subscription, select Continuous Export, set the export target to the Log Analytics workspace, and set the data types to Security recommendations and Secure Score (Preview) and leave the export frequency at the default values.

![Microsoft Defender for Cloud Configuration](./security_center_config_3.png)

- Make sure to select ArcBox's subscription, resource group, and Log Analytics workspace as the export target. Select Save.

![Microsoft Defender for Cloud Configuration](./security_center_config_4.png)

Once configured, the report will provide an overview of the secure score, you can filter information by using the parameters section:

- _Workspace_ - Select one or multiple Log Analytics workspaces.

- _Time Range_ - Filter the data of the report to one of the predefined time ranges.

![Security parameters](./security_parameters.png)

With this report you will get several visualizations:

- _Current score trends per subscription_

![Security workbook trends](./security_trends.png)

- _Aggregated score for selected subscriptions over time_

![Security workbook aggregated score](./security_score.png)

- _Top recommendations with the recent increase in unhealthy resources_

![Security tab top recommendations](./security_recommendations.png)

- _Security controls scores over time (weekly)_

![Security controls scores overtime](./security_controls.png)

- _Resources changed over time_ - To view changes over time on a specific recommendation, please select any from the list above.

![Resources changed overtime](./security_changes.png)

![Resources changed overtime selected resources](./security_changes_resource.png)

This part of the workbook also includes a section dedicated to agent monitoring. For Azure Defender to be able to monitor an Azure Arc-enabled-servers certain configurations have to be in place and the workbook will help visualize machines that may not be properly reporting to the Log Analytics workspace.

In the parameters section select the Log Analytics workspace used by ArcBox.

![Agent Management](./agentmgmt_parameters.png)

From within the Agent Monitoring section you will get several tabs:

- _Overview_ - with three visualizations:

- _Azure Monitor Agent installation status_ shows the Azure Monitor Agent installation status as reported by Microsoft Defender for Cloud.

![Azure Monitor Agent installation status](./agentmgmt_overviewstatus.png)

- _Azure Monitor Agent reporting status_ shows the current Azure Monitor Agent reporting status of the Azure Arc-enabled servers. Machines that are sending current heartbeat information within the last 15 minutes are considered as currently reporting.
The _Azure Arc-enabled servers OS Performance_ Workbook shows metrics and alerts for ArcBox for IT Pros resources organized in three sections:

![Azure Monitor Agent reporting status](./agentmgmt_overviewsreport.png)
- _Operating System - Performance and capacity_ - Shows metrics for CPU and memory usage on the Azure Arc-enabled servers.

- _Azure Defender coverage_ shows the status of Azure Defender for Servers across all servers that are protected by Microsoft Defender for Cloud.
**CPU metrics**

![Azure Defender coverage](./agentmgmt_overviewscoverage.png)
![Monitoring Azure Arc-enabled server Metrics](./monitoring_arc_servers_01.png)

- _Machines not reporting to Log Analytics workspace_ - this has four lists of machines that are not sending heartbeats to the Log Analytics workspace in different periods of time: 15 minutes, 24 hours, 48 hours and 7 days. Please not that there are no machines listed on the image as all of them are properly sending heartbeats to the workspace.
**Memory metrics**

![Machines not reporting](./agentmgmt_machinesnotreport.png)
![Monitoring Azure Arc-enabled server Metrics](./monitoring_arc_servers_02.png)

- _Security status_ - has a full report of Azure VMs and Azure Arc-enabled-servers security configurations including its Log Analytics workspace and the agent status.
**Disk metrics**

![Security Status](./agentmgmt_securitystatus.png)
![Monitoring Azure Arc-enabled server Metrics](./monitoring_arc_servers_03.png)
Loading