The IT environment acts as a security boundary for the following data within a OneIQ account:
Application metrics, traces, and logs
Billing data from AWS, Azure, and GCP
Users can see each IT environment inside their OneIQ account and in the OneIQ workspaces they are connected to.
Connecting the IT environment to a workspace
Workspaces enable internal teams, trusted advisors, and suppliers to have a secure, shared context around the connected IT environment, eliminating the need to give users access to internal systems, set up VPNs, or ship data to third parties.
Access policy
When the IT environment is connected to the workspace, the following access policies can be used to scope access to the data:
Platforms
Applications
Costs
Time
Asset-identifiable data such as hostnames can be scrambled. Account members and owners will continue to have access to unscrambled data.
Application data
Application metrics, traces, and logs can be streamed to OneIQ Central using OpenTelemetry
Infrastructure data
Hybrid IT infrastructure configuration, performance, and network data are streamed in real-time for container, cloud, and data center platforms profiled by OneIQ Pulse connectors. Each OneIQ Pulse is linked to an IT environment using a unique connection key.
The connection key must be entered into each OneIQ Pulse connector for data center platforms:
For container and cloud flavors of OneIQ Pulse, the connection key is embedded in the download template.
Data storage
Application, billing, and infrastructure data for each IT environment is stored in the OneIQ Central data warehouse, hosted on Microsoft Azure Storage in the Canada Central region with geo-replication and encryption-at-rest.
Note: enterprise customers have the option to store data in their Microsoft Azure environment.