# Amazon EBS Volumes

{% embed url="<https://www.youtube.com/watch?v=xX6psnJHyzI>" %}

## Architecture

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FzBZLOztRiQTsOKribLL7%2Febs_scanning.png?alt=media&#x26;token=a2eb3fda-ce1b-47e8-a4bf-5b48406c0c2a" alt=""><figcaption></figcaption></figure>

1. The Console Service creates an EC2 instance in the EBS Volume region as a Scanning Agent
2. The Agent creates an EBS Snapshot
3. The EBS Snapshot is scanned by the Scanning Agent
4. Results are sent to CloudWatch
5. Job status and other scan details are sent to DyanamoDB
6. The Console service ingests details from CloudWatch and DyanamoDB, and when the scan is done, scanning architecture and the EBS Snapshot are torn down

## Console EBS Protection Page

The EBS Protection page will show you any EBS volumes that are associated with the account that you have deployed our solution in, as well as volumes from any accounts linked to your console. Here you'll be able to create Antivirus scanning and Data Classification schedules for EBS Volumes.

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2Fy5ege4UaeYsgZxZSvZWU%2FScreenshot%202023-11-17%20at%204.40.56%20PM.png?alt=media&#x26;token=71292b2e-51b5-48df-b5ce-2eab40054a47" alt=""><figcaption></figcaption></figure>

## Setting up your VPC and Subnets for the regions you are protecting EBS volumes in

If you do not have a VPC and subnets staged in the region your EBS Volumes exist in, you will be asked to set a VPC and subnets when activating the schedule. You can learn more about staging regions in the [Event Agent Settings](https://help.cloudstoragesec.com/configuration/agent-settings#staged-regions) page.

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2F3HtdHr7lxVV053c1glSY%2Fnetwork.gif?alt=media&#x26;token=847d6136-35e3-4ab2-b886-9cc7828c0163" alt=""><figcaption><p>VPC and Subnets</p></figcaption></figure>

## Creating an EBS volume scan or classification schedule

You can create a schedule within the [Schedules page](https://help.cloudstoragesec.com/console-overview/scheduled-scans), or you can create a schedule for EBS volumes directly from the EBS Volumes page.

1. Select the EBS volume(s) you want to protect through a schedule
2. Click actions and select either `Create AV Schedule` or `Create DC Schedule`
3. You can select any additional EBS volumes and add EFS volumes or S3 buckets to the schedule through the schedule popup
4. Once you have all of the resources you want to add to a schedule selected, click on the `Create Schedule` tab
5. Name your schedule, add the scan period and make any additional changes you need
6. Click `Save` once you're done

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FgRxnr6vVvf8s8RReqtcf%2Febs.gif?alt=media&#x26;token=45840940-338e-4b26-b5e5-c359ead252ef" alt=""><figcaption><p>Create your Schedule</p></figcaption></figure>

After your schedule is created you'll want to go to the Schedules page and activate the schedule.

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FS7p7t0ZnUl6pAiEflAgB%2Fschedule.gif?alt=media&#x26;token=71d21e49-8a9d-469f-a7a9-bba956d02c6a" alt=""><figcaption><p>Activate your Schedule</p></figcaption></figure>

Now your schedule will run per the scan period that you originally configured. If you need to add or remove volumes, or make any other configuration changes you can always edit the schedule on the `Schedules` page.

## Volume Schedule Statuses

The schedule icons shown below will reflect whether a bucket is associated with a schedule and whether that schedule is active or not.

* Protected by Active Schedule - ![Green clock](https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FcWjXBZghM895Qpeu9Zr7%2Fgreen-clock.png?alt=media)
* Part of an **Inactive** Schedule - ![Red clock](https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FD1I4zDFdWHhwv79Ma0Zi%2Fyellow-clock.png?alt=media)
* Not a Part of any Schedule - ![Red clock](https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2FLAvOVzethjMYhwSe7V27%2Fred-clock.png?alt=media)

## On-demand antivirus scanning and data classification

<figure><img src="https://905555942-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlGcQw8I2CHyi1loKBlfi%2Fuploads%2Fy7Qg6zGUF9ZXiH1wsrO1%2FScreenshot%202024-04-14%20at%2021.52.14.png?alt=media&#x26;token=c79a1c9d-0855-446c-9b3d-550a81200dca" alt=""><figcaption><p>EBS On-demand Scanning</p></figcaption></figure>

In addition to scheduled scans, you can select and perform on-demand AV and DC scanning for EBS volumes.
