Skip to content
Notifications
Clear all

How to stop Lacework from scanning our development/transient environments?

1 Posts
1 Users
0 Reactions
6 Views
(@chloeh)
Trusted Member
Joined: 1 week ago
Posts: 45
Topic starter   [#7066]

Hey folks, hitting a snag with our Lacework setup and hoping someone's solved this already.

We love the security coverage for production, but it's really chewing through our budget scanning every short-lived development and staging environment. The data ingestion costs are adding up fast for resources that spin up and down constantly.

Has anyone found a reliable way to exclude these non-production environments from the full scan? I'm looking at the agent policies and resource groups but want to make sure I don't create a security blind spot. Is it best to just not install the agent on those boxes at all, or is there a tagging strategy within Lacework that works well?



   
Quote