Device Labels

Device Labels serve as a powerful and flexible tool to differentiate devices, even when they appear identical or very similar across various environments or sites. These labels are user-definable, allowing you to assign unique identifiers based on parameters like location name, manufacturing line name, device owner, zone name, or any custom string of text. Labels are fully customizable and can be applied to as many devices as needed, giving you the ability to group devices of any type. Multiple labels can be applied to the same device. The primary objective of device labels is to offer an additional mechanism to distinctly identify a device or a set of devices. For instance, in a scenario where an environment houses multiple identical devices, Device Labels can be invaluable. By matching these identifying attributes in a policy group, users can segregate these devices into distinct policy groups, each governed by its unique set of policies.

Example A: Imagine a manufacturing company with identical PLCs across multiple production lines. While the PLCs are identical in function, they might be used for different tasks based on the production line and require unique security policies. By using Device Labels like "Line A" or "Line B", the company can easily categorize these PLCs and apply specific policies to each group, ensuring smooth operations and enhanced security.

Example B: A Device Label can also be used to architect your device groupings and policies to meet specific standards as they pertain to segmentation. For example, IEC 62443 Zones, Sub-Zones and Conduits can be defined by associating a label (Zone/Sub-Zone or any custom name) with a device and then matching on that Device Label in a policy group to design the segmentation of the network to meet the security requirements of the business.

Elisity offers complete flexibility when it comes to match criteria for a Policy Group. In this scenario, we are only using manually defined attributes such as Site Label and Device Label to group devices into their respective segments. These two attributes, when leveraged together take things further and allow you to differentiate between similar environments across different sites. Site Label and Device Label are static attributes and do not change unless manually adjusted, meaning the classification of the device will never change dynamically.

Managing Device Labels

Device labels are managed objects that you create and organize from the Label Library. Navigate to Settings > System and select the Label Library tab. Each label has a name, an optional description, and a color that is used to display the label throughout Cloud Control Center. Labels can be grouped into folders to keep large label sets organized; folders are an organizational convenience only and do not affect policy or device matching.

The Label Library lists every label along with the following details.

Column Description
Label Name The name of the label, shown with its assigned color.
Origin How the label was created, such as User for a label created manually in Cloud Control Center.
Device Count The number of devices the label is currently applied to. Select the count to open the Devices page filtered to those devices.
Description The optional description entered when the label was created.
Actions The menu for editing, moving, or deleting the label.

To create a label, select Create Label. In the Create Labels Manually drawer, enter a Label Name, add an optional Description, choose a Folder, and select a color. Select Add Another Label to define several labels in the same drawer, then select Create.

Use the Search box and filters to locate labels by name, and select Add Folder to create folders for grouping. You can select multiple labels to move or delete them in a single operation; when you delete a label, Cloud Control Center shows the devices it is currently applied to before you confirm. Label definitions can also be imported in bulk from a spreadsheet that specifies each label's parent folder, name, color, and description.

Methods of Adding/Importing Device Labels

Several methods are available for assigning device labels.

1. Imported via Open Connector (preferred method)

For customers leveraging Elisity's Open Connector, we recommend importing these labels from the "Label" attribute in the Open Connector. See our Open Connector API Specifications article for details.

2. Manually Configured

Follow the steps below to manually configure device labels in Cloud Control Center. Options are available for bulk updating assets with labels using spreadsheet import.

Steps to Manually Configure Device Labels

Step 1: Log into Cloud Control Center and navigate to the Devices section. Select the device or devices you want to apply a label to, then choose Bulk Actions (or open a single device and select Edit).

Step 2: Under the Attributes Configuration section, select one or more managed device labels in the Label field and select Save Changes. To use a label that does not yet exist, type its name and select Add Label; the Create Labels Manually drawer opens with the name already filled in so you can finish defining the label.

When you edit multiple devices at once, the same Label field appears in the Bulk Edit panel and applies your label selections across every selected device in a single operation. Select Submit to apply the changes.

After saving the changes you can select the device you just added the label to and see that it is reflected under the Manually Configured section.

Step 3: Now that the Device Label has been defined, you can reference it as match criteria in a policy group. Any device that matches all conditions of the policy group, including the label, will be classified into that policy group and receive all associated policies. Specify the Device label as a part of your match criteria and select Create.

Here you can see the full set of match criteria for this particular example.

Updating Device Labels by Spreadsheet Import

You can update the Device Labels for a list of select devices by uploading a spreadsheet with the Device Label field filled out, comma separated if adding multiple. One mandatory field that must be populated in the spreadsheet and match the discovered devices you want to update is MAC Address.

Step 1: Navigate to the Devices page in Cloud Control Center and select Add Device > Add Multiple Devices.

Step 2: In the slide out drawer, select Download Sample and open the spreadsheet. Fill out the mandatory field and add the Device Label to all of the devices and save the changes.

Step 3: Go back to the Add Multiple Devices page and select Click to upload, and upload the spreadsheet. Click Submit.

Was this article helpful?
0 out of 0 found this helpful