The Client Group Association tab allows you to enable association of any Client Group configured in the Manager at the domain level or device level. This tab is available in the following two places in the Manager:
The → → → → → tab helps in enabling the association of any Client Group for the admin domain as well as child domains. If you enable the NI integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain.
The → → → → → → tab helps in enabling the association of any Client Group per Sensor basis within any domain, thus allowing further customization of NI integration settings.
For example, assume that you have enabled the association of Client Group A for a child parent domain X which has Sensor 1, Sensor 2 and Sensor 3 attached to it. In Client Group A, you have enabled L7 metadata configuration for both HTTP and HTTPS protocols. Once the Client Group A is associated with X domain, all the three Sensors will inherit this settings. However, you wish to analyze only HTTPS protocol specific metadata in the netflows sent by Sensor 2 on the NI. In such a case, you can configure another Client Group with the desired l7 metadata configuration on the NI CLI and perform the configuration and association of that Client Group for Sensor 2 only in the Manager.
Note
Configuring a Client Group in Manager is mandatory prior to its association either at domain level or device level. If you have not configured it using the Client Group Configuration tab at the Global level, you can do it via the Client Group Association tabs available at both Global and Device levels.