View Workload Manager rule findings

Viewing Workload Manager rule findings in Compute Engine lets you identify configuration risks and best practice violations across your virtual machine (VM) fleet directly within your daily infrastructure management workflows.

This page describes how to view Workload Manager rule findings on the Compute Engine Overview page.

To learn more about Workload Manager rule findings, see About Workload Manager rule findings.

Before you begin

Before you view Workload Manager rule findings, ensure that you meet the following prerequisites:

Required roles

To get the permissions that you need to view Workload Manager rule findings in Compute Engine, ask your administrator to grant you the following IAM roles on your project:

For more information about granting roles, see Manage access to projects, folders, and organizations.

These predefined roles contain the permissions required to view Workload Manager rule findings in Compute Engine. To see the exact permissions that are required, expand the Required permissions section:

Required permissions

The following permissions are required to view Workload Manager rule findings in Compute Engine:

  • View the Compute Engine Overview page: compute.projects.get
  • View Workload Manager findings: workloadmanager.findings.list

You might also be able to get these permissions with custom roles or other predefined roles.

For more information about Workload Manager roles, see Workload Manager IAM roles and permissions.

Enable Workload Manager

If you haven't enabled Workload Manager for your project, the Workload Manager findings tile on the Compute Engine Overview page prompts you to enable the service. Activating the service lets you view configuration risks and compliance violations directly on the Overview page.

To enable Workload Manager from the Compute Engine Overview page, do the following:

  1. In the Google Cloud console, go to the Compute Engine Overview page.

    Go to Overview

  2. Locate the Workload Manager findings tile.

  3. Click Activate Workload Manager.

Alternatively, you can enable the Workload Manager API directly. For more information, see Enable Workload Manager.

Create an evaluation

If you haven't created or received shared evaluations in Workload Manager for your project, the Workload Manager findings tile prompts you to create an evaluation. To generate rule findings for your resources, you must create and run an evaluation.

To create an evaluation from the Compute Engine Overview page, do the following:

  1. In the Google Cloud console, go to the Compute Engine Overview page.

    Go to Overview

  2. Locate the Workload Manager findings tile.

  3. Click Create evaluation.

  4. Follow the prompts to configure and run your evaluation. For detailed instructions, see Create and run an evaluation.

Interpret rule findings

The Workload Manager findings tile displays aggregated rule findings for your resources. The tile categorizes findings by severity level and impact category to help you prioritize remediation efforts.

Severity levels

When you run an evaluation, Workload Manager evaluates resources by comparing their current state with best practices. If a resource doesn't comply with a selected best practice, Workload Manager assigns it a severity level that indicates how far the resource is out of compliance. The Google Cloud console marks each non-compliant resource with an icon. The following table explains these icons, their corresponding severity levels, how the current resource setting might impact your workload, and recommendations for modifying the resource to adhere to best practices.
Icon Severity level Impacts Recommendation
Critical System Reliability, Unplanned Outages, Unsupported Configuration

Resolve as soon as possible to prevent an impact on system availability and data integrity due to a high risk of an unplanned outage.

High Degraded Performance, System Stability Resolve during the next planned maintenance window.
Medium Suboptimal Performance, Supportability Resolve at your earliest convenience.
Low Informational, Non-essential Behavior Although there's no resolution needed, reviewing this best practice can provide useful insights.

Impact categories

The following table describes the impact categories used to classify Workload Manager findings:
Category Description
Reliability Findings related to workload availability, fault tolerance, and backup configurations.
Security Findings related to access controls, encryption, and compliance with best practices for security.
Performance Findings related to resource utilization, latency, and system optimization.
Cost Findings related to underutilized resources and opportunities to optimize operational expenses.

View detailed findings

To view details of specific rule findings, you can navigate from the Workload Manager findings tile on the Compute Engine Overview page directly to the Workload Manager dashboard.

To view detailed rule findings in Workload Manager:

  1. In the Google Cloud console, go to the Overview page.

    Go to Overview

  2. Click View all findings or select a specific severity level to open the Workload Manager Rule findings tab.

  3. In the findings table, click the name of a specific finding to view its description, affected resources, and recommended remediation steps.

Troubleshoot

For help with diagnosing and resolving issues related to Workload Manager evaluations, see Troubleshoot Workload Manager evaluations.

What's next