Handle Excluded Certificates During Certificate Ingestion

Use this procedure to ensure certificates already present in Excluded Certificates inventory are not added again to the main inventory when certificates enter AppViewX through Config Sync, KUBE, or Cloud integrations.

  • Certificate ingestion is enabled through one or more sources: Config Sync, KUBE, or Cloud integrations.
  • The certificates that must be blocked from main inventory are available in Excluded Certificates inventory.
  1. Go to Menu > KUBE > VISIBILITY > Client > Excluded Certificates, and verify that the certificate(s) to be excluded are already present.
    The target certificate entries are confirmed in Excluded Certificates inventory.
  2. Trigger or wait for certificate ingestion from Config Sync, KUBE, or Cloud integration.
    Certificate ingestion processing is initiated for incoming certificates.
  3. Go to Menu > KUBE > VISIBILITY > Client > All, and search for the excluded certificate(s).
    The excluded certificate entries are not added to the main inventory.
  4. Validate operational status or logs for the ingestion run, if required by your workflow.
    The ingestion run completes without adding excluded certificates to the main inventory.

Certificates listed in Excluded Certificates inventory are filtered out when they enter AppViewX through Config Sync, KUBE, or Cloud integrations, and are not created in main certificate inventory.

Note: If an excluded certificate appears in main inventory, review exclusion entry accuracy and ingestion source mapping before rerunning discovery or sync.