N2WS CPM
Visualize your N2WS Backup & Recovery (CPM) deployment in JupiterOne — the AWS accounts configured in CPM, backup policies and the schedules they use, the resources each policy protects, and resource control (power management) groups with the EC2 instances and RDS databases they start and stop — map CPM accounts and protected resources to the AWS accounts, instances, volumes, and databases ingested by the JupiterOne AWS integration, find AWS resources that no backup policy protects, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
Installation
This integration connects to your N2WS Backup & Recovery (CPM) server using the N2WS RESTful API and ingests the AWS accounts configured in CPM, backup policies, backup schedules, protected resources, and resource control (power management) groups with the resources they manage. The CPM server runs in your own AWS VPC and is usually reachable only from inside it, so the integration normally runs on a JupiterOne Collector that can reach the server's API over HTTPS (port 443 by default).
The integration authenticates with an API Authentication Key. It exchanges the key at POST /api/token/obtain/api_key/ for a one-hour access token, sends that token as an Authorization: Bearer header on every request, and obtains a new one automatically when it expires. The integration only issues read requests.
Configuration in N2WS
Before you configure the integration in JupiterOne, prepare the following in the N2WS console:
- The hostname or IP address of your CPM server. The JupiterOne Collector must be able to reach it over HTTPS.
- A CPM user to own the API key. The key acts as that user: the integration only sees the accounts, policies, and resources that user can see, so a key created by a delegate of a managed user only returns that managed user's data. N2WS recommends a dedicated delegate user. If you create the delegate with all of its permission options cleared, it is a read-only user that can list information such as policies but cannot change configuration or run recoveries, which is all the integration needs.
- An API Authentication Key for that user. Sign in to the console as the user, enable API access, and generate the key. The menu location differs between N2WS versions, so see A Beginner's Guide to N2W RESTful API for the steps. The key is only used to obtain access tokens.
- If the server presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.
Once you have obtained the information above, proceed to JupiterOne to finalize the integration.
Configuration in JupiterOne
To install the N2WS CPM integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select N2WS CPM. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the N2WS CPM account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The CPM Host (required): the hostname or IP address of your CPM server, optionally with a
:port, for examplecpm.example.internal. Do not include a path. If you paste a URL such ashttps://cpm.example.internal/api/, thehttps://prefix, trailing slash, and/apisuffix are removed automatically. -
The API Authentication Key (required) generated above.
-
Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended). Both are empty by default.
The integration validates the configuration by obtaining an access token and listing the AWS accounts in CPM, so the key's user must be able to list accounts.
Data Sources
Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest. The CPM server itself is always ingested as an n2ws_account entity.
| Data Source | Description | Entities Created |
|---|---|---|
| Backup Accounts | AWS accounts configured in N2WS CPM | n2ws_backup_account |
| Backup Policies | N2WS CPM backup and DR policies | n2ws_policy |
| Backup Schedules | N2WS CPM backup schedules | n2ws_schedule |
| Resource Control (Power Management) | N2WS CPM resource control groups and the EC2 instances and RDS databases they power-manage | n2ws_resource_control_group, n2ws_power_managed_resource |
| Protected Resources | AWS resources covered by an N2WS CPM backup policy | n2ws_protected_resource |
The relationships between data sources are built only when both sides are enabled:
- Backup account to policy (
HAS) requires Backup Accounts and Backup Policies. - Backup account to resource control group (
HAS) requires Backup Accounts and Resource Control (Power Management). - Policy to schedule (
USES) requires Backup Policies and Backup Schedules. - Policy to protected resource (
PROTECTS) requires Backup Policies and Protected Resources. - Schedule to protected resource (
HAS) requires Backup Schedules and Protected Resources.
CPM reports the policies and schedules covering a protected resource by name, so a protected resource is linked to a policy or schedule only when exactly one ingested policy or schedule has that name.
Relationships to AWS entities
The integration links CPM data to the AWS entities ingested by the JupiterOne AWS integration through mapped relationships. It never creates AWS entities itself, so these relationships only appear for AWS accounts that the AWS integration also ingests.
| Source | Relationship | AWS entity | Matched on |
|---|---|---|---|
n2ws_backup_account | IS | aws_account | AWS account number |
n2ws_protected_resource (EC2 instance) | PROTECTS | aws_instance | Instance ID |
n2ws_protected_resource (independent EBS volume) | PROTECTS | aws_ebs_volume | Volume ID |
n2ws_protected_resource (RDS) | PROTECTS | aws_db_instance | DB instance identifier |
n2ws_protected_resource (Aurora) | PROTECTS | aws_rds_cluster | DB cluster identifier |
n2ws_protected_resource (Redshift) | PROTECTS | aws_redshift_cluster | Cluster identifier |
n2ws_power_managed_resource (EC2 instance) | MANAGES | aws_instance | Instance ID |
n2ws_power_managed_resource (RDS database) | MANAGES | aws_db_instance | DB instance identifier |
Only EC2 instances, independent EBS volumes, RDS instances, Aurora clusters, and Redshift clusters are linked to AWS entities. Other resource types that CPM can back up, such as EFS, DynamoDB, FSx, and DocumentDB, are not linked to AWS entities.
Because coverage is expressed as relationships to AWS entities, a query for unprotected resources is only meaningful for AWS accounts that the AWS integration ingests. For example, with the Protected Resources data source enabled, the following query lists EC2 instances that no CPM protected resource covers:
FIND aws_instance THAT !PROTECTS n2ws_protected_resource
With Backup Policies also enabled, the following query lists EC2 instances together with the CPM policy that protects them:
FIND n2ws_policy THAT PROTECTS n2ws_protected_resource THAT PROTECTS aws_instance
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (8)
https://<cpm-host>/api/aws/accounts/https://<cpm-host>/api/aws/policies/https://<cpm-host>/api/aws/reports/protected_resources/https://<cpm-host>/api/aws/resource_control/groups/https://<cpm-host>/api/aws/resource_control/groups/{group_id}/targets/instances/https://<cpm-host>/api/aws/resource_control/groups/{group_id}/targets/rds_databases/https://<cpm-host>/api/schedules/https://<cpm-host>/api/version/
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (1)
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (1)
| Step | Endpoints |
|---|---|
| Fetch Power-Managed Resources | https://<cpm-host>/api/aws/resource_control/groups/{group_id}/targets/instances/, https://<cpm-host>/api/aws/resource_control/groups/{group_id}/targets/rds_databases/ |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Backup Policy | n2ws_policy | Policy |
| Backup Schedule | n2ws_schedule | Configuration |
| CPM Backup Account | n2ws_backup_account | Account |
| CPM Service | n2ws_account | Service |
| Power-Managed Resource | n2ws_power_managed_resource | Resource |
| Protected Resource | n2ws_protected_resource | Resource |
| Resource Control Group | n2ws_resource_control_group | Group |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
n2ws_account | HAS | n2ws_backup_account |
n2ws_backup_account | HAS | n2ws_policy |
n2ws_backup_account | HAS | n2ws_resource_control_group |
n2ws_policy | USES | n2ws_schedule |
n2ws_policy | PROTECTS | n2ws_protected_resource |
n2ws_resource_control_group | MANAGES | n2ws_power_managed_resource |
n2ws_schedule | HAS | n2ws_protected_resource |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
n2ws_backup_account | IS | aws_account | FORWARD |
n2ws_power_managed_resource | MANAGES | aws_instance | FORWARD |
n2ws_power_managed_resource | MANAGES | aws_db_instance | FORWARD |
n2ws_protected_resource | PROTECTS | aws_instance | FORWARD |
n2ws_protected_resource | PROTECTS | aws_ebs_volume | FORWARD |
n2ws_protected_resource | PROTECTS | aws_db_instance | FORWARD |
n2ws_protected_resource | PROTECTS | aws_rds_cluster | FORWARD |
n2ws_protected_resource | PROTECTS | aws_redshift_cluster | FORWARD |
N2ws Account
n2ws_account inherits from Service
| Property | Type | Description | Specifications |
|---|---|---|---|
cpmHost * | string | Hostname of the N2WS CPM appliance. | |
version * | string | null | CPM appliance software version. |
N2ws Backup Account
n2ws_backup_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
accountNumber * | string | null | The 12-digit AWS account number. | |
authentication * | string | null | Authentication method: C (IAM user), R (IAM role), A (assume role). | |
awsCloud * | string | null | AWS cloud: S (standard), G (GovCloud), C (China). | |
isCaptureVpcsEnabled * | boolean | null | Whether CPM captures VPC settings for this account. | |
isDrAccount * | boolean | null | Whether this account is used as a DR (disaster recovery) target. | |
isScanTaggedResourcesEnabled * | boolean | null | Whether CPM scans tagged resources for backup in this account. |
N2ws Policy
n2ws_policy inherits from Policy
| Property | Type | Description | Specifications |
|---|---|---|---|
autoRemoveResource * | string | null | Auto-remove behaviour for resources: N (no), Y (yes), A (ask). | |
backupRetentionTimeUnit * | string | null | Time unit for backup retention. | |
backupRetentionTimeValue * | number | null | Backup retention time value. | |
drGenerations * | number | null | Number of DR backup generations retained. | |
drRetentionTimeUnit * | string | null | Time unit for DR backup retention. | |
drRetentionTimeValue * | number | null | DR backup retention time value. | |
generations * | number | null | Number of backup generations retained. | |
isCopyToS3Enabled * | boolean | null | Whether backups are copied to S3. | |
isCreatedByTag * | boolean | null | Whether the policy was created by a tag-scan. | |
isDrEnabled * | boolean | null | Whether disaster recovery is enabled for the policy. | |
isEnabled * | boolean | null | Whether the policy is enabled. |
N2ws Power Managed Resource
n2ws_power_managed_resource inherits from Resource
| Property | Type | Description | Specifications |
|---|---|---|---|
awsRegion * | string | null | The AWS region the resource resides in. | |
awsResourceId * | string | null | The AWS id of the power-managed resource. | |
awsResourceType * | string | null | The AWS resource type reported by CPM. | |
resourceType * | string | null | CPM resource type of the target. | |
state * | string | null | Current state (EC2) or status (RDS) of the resource as reported by CPM. | |
targetKind * | string | Which Resource Control target list the resource came from: instance (EC2) or rds_database (RDS). |
N2ws Protected Resource
n2ws_protected_resource inherits from Resource
| Property | Type | Description | Specifications |
|---|---|---|---|
accountName * | string | null | The CPM account name the resource belongs to. | |
awsRegion * | string | null | The AWS region the resource resides in. | |
awsResourceId * | string | null | The AWS id of the protected resource. | |
awsResourceName * | string | null | The AWS name of the protected resource. | |
isPartial * | boolean | null | Whether the resource is only partially protected. | |
resourceType * | string | null | CPM resource type: instance, independent_volume, rds, aurora, or redshift. |
N2ws Resource Control Group
n2ws_resource_control_group inherits from Group
| Property | Type | Description | Specifications |
|---|---|---|---|
isEnabled * | boolean | null | Whether the group is enabled. | |
isHibernate * | boolean | null | Whether the group hibernates instances when stopping. | |
operationMode * | string | null | Operation mode of the group: on-off or off. | |
timeout * | number | null | Operation timeout in seconds. |
N2ws Schedule
n2ws_schedule inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
endedOn * | number | null | Schedule end time (epoch milliseconds, UTC). | |
everyHowMany * | number | null | How many frequency units between runs. | |
everyUnit * | string | null | Frequency unit: M (minutes), H (hours), D (days), W (weeks), O (months). | |
isAllowedOnFriday * | boolean | null | Whether the schedule may run on Friday. | |
isAllowedOnMonday * | boolean | null | Whether the schedule may run on Monday. | |
isAllowedOnSaturday * | boolean | null | Whether the schedule may run on Saturday. | |
isAllowedOnSunday * | boolean | null | Whether the schedule may run on Sunday. | |
isAllowedOnThursday * | boolean | null | Whether the schedule may run on Thursday. | |
isAllowedOnTuesday * | boolean | null | Whether the schedule may run on Tuesday. | |
isAllowedOnWednesday * | boolean | null | Whether the schedule may run on Wednesday. | |
startedOn * | number | null | Schedule start time (epoch milliseconds, UTC). | |
timezone * | string | null | Timezone the schedule evaluates in. |