Skip to content

Commit 89a11c5

Browse files
authored
roles yml changes for security-analytics plugin (#2192)
* roles yml changes for security-analytics plugin Signed-off-by: Raj Chakravarthi <raj@icedome.ca> Signed-off-by: Raj Chakravarthi <49325334+raj-chak@users.noreply.github.com>
1 parent a040b86 commit 89a11c5

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed

config/roles.yml

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,3 +255,38 @@ point_in_time_full_access:
255255
- '*'
256256
allowed_actions:
257257
- 'manage_point_in_time'
258+
259+
# Allows users to see security analytics detectors and others
260+
security_analytics_read_access:
261+
reserved: true
262+
cluster_permissions:
263+
- 'cluster:admin/opensearch/securityanalytics/alerts/get'
264+
- 'cluster:admin/opensearch/securityanalytics/detector/get'
265+
- 'cluster:admin/opensearch/securityanalytics/detector/search'
266+
- 'cluster:admin/opensearch/securityanalytics/findings/get'
267+
- 'cluster:admin/opensearch/securityanalytics/mapping/get'
268+
- 'cluster:admin/opensearch/securityanalytics/mapping/view/get'
269+
- 'cluster:admin/opensearch/securityanalytics/rule/get'
270+
- 'cluster:admin/opensearch/securityanalytics/rule/search'
271+
272+
# Allows users to use all security analytics functionality
273+
security_analytics_full_access:
274+
reserved: true
275+
cluster_permissions:
276+
- 'cluster:admin/opensearch/securityanalytics/alerts/*'
277+
- 'cluster:admin/opensearch/securityanalytics/detector/*'
278+
- 'cluster:admin/opensearch/securityanalytics/findings/*'
279+
- 'cluster:admin/opensearch/securityanalytics/mapping/*'
280+
- 'cluster:admin/opensearch/securityanalytics/rule/*'
281+
index_permissions:
282+
- index_patterns:
283+
- '*'
284+
allowed_actions:
285+
- 'indices:admin/mapping/put'
286+
- 'indices:admin/mappings/get'
287+
288+
# Allows users to view and acknowledge alerts
289+
security_analytics_ack_alerts:
290+
reserved: true
291+
cluster_permissions:
292+
- 'cluster:admin/opensearch/securityanalytics/alerts/*'

0 commit comments

Comments
 (0)