Keine Beschreibung

roles.yml 4.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171
  1. _meta:
  2. type: "roles"
  3. config_version: 2
  4. # Restrict users so they can only view visualization and dashboards on kibana
  5. kibana_read_only:
  6. reserved: true
  7. # The security REST API access role is used to assign specific users access to change the security settings through the REST API.
  8. security_rest_api_access:
  9. reserved: true
  10. # Allows users to view monitors, destinations and alerts
  11. alerting_read_access:
  12. reserved: true
  13. cluster_permissions:
  14. - 'cluster:admin/opendistro/alerting/alerts/get'
  15. - 'cluster:admin/opendistro/alerting/destination/get'
  16. - 'cluster:admin/opendistro/alerting/monitor/get'
  17. - 'cluster:admin/opendistro/alerting/monitor/search'
  18. # Allows users to view and acknowledge alerts
  19. alerting_ack_alerts:
  20. reserved: true
  21. cluster_permissions:
  22. - 'cluster:admin/opendistro/alerting/alerts/*'
  23. # Allows users to use all alerting functionality
  24. alerting_full_access:
  25. reserved: true
  26. cluster_permissions:
  27. - 'cluster_monitor'
  28. - 'cluster:admin/opendistro/alerting/*'
  29. index_permissions:
  30. - index_patterns:
  31. - '*'
  32. allowed_actions:
  33. - 'indices_monitor'
  34. - 'indices:admin/aliases/get'
  35. - 'indices:admin/mappings/get'
  36. # Allow users to read Anomaly Detection detectors and results
  37. anomaly_read_access:
  38. reserved: true
  39. cluster_permissions:
  40. - 'cluster:admin/opendistro/ad/detector/info'
  41. - 'cluster:admin/opendistro/ad/detector/search'
  42. - 'cluster:admin/opendistro/ad/detectors/get'
  43. - 'cluster:admin/opendistro/ad/result/search'
  44. - 'cluster:admin/opendistro/ad/tasks/search'
  45. # Allows users to use all Anomaly Detection functionality
  46. anomaly_full_access:
  47. reserved: true
  48. cluster_permissions:
  49. - 'cluster_monitor'
  50. - 'cluster:admin/opendistro/ad/*'
  51. index_permissions:
  52. - index_patterns:
  53. - '*'
  54. allowed_actions:
  55. - 'indices_monitor'
  56. - 'indices:admin/aliases/get'
  57. - 'indices:admin/mappings/get'
  58. # Allows users to read Notebooks
  59. notebooks_read_access:
  60. reserved: true
  61. cluster_permissions:
  62. - 'cluster:admin/opendistro/notebooks/list'
  63. - 'cluster:admin/opendistro/notebooks/get'
  64. # Allows users to all Notebooks functionality
  65. notebooks_full_access:
  66. reserved: true
  67. cluster_permissions:
  68. - 'cluster:admin/opendistro/notebooks/create'
  69. - 'cluster:admin/opendistro/notebooks/update'
  70. - 'cluster:admin/opendistro/notebooks/delete'
  71. - 'cluster:admin/opendistro/notebooks/get'
  72. - 'cluster:admin/opendistro/notebooks/list'
  73. # Allows users to read and download Reports
  74. reports_instances_read_access:
  75. reserved: true
  76. cluster_permissions:
  77. - 'cluster:admin/opendistro/reports/instance/list'
  78. - 'cluster:admin/opendistro/reports/instance/get'
  79. - 'cluster:admin/opendistro/reports/menu/download'
  80. # Allows users to read and download Reports and Report-definitions
  81. reports_read_access:
  82. reserved: true
  83. cluster_permissions:
  84. - 'cluster:admin/opendistro/reports/definition/get'
  85. - 'cluster:admin/opendistro/reports/definition/list'
  86. - 'cluster:admin/opendistro/reports/instance/list'
  87. - 'cluster:admin/opendistro/reports/instance/get'
  88. - 'cluster:admin/opendistro/reports/menu/download'
  89. # Allows users to all Reports functionality
  90. reports_full_access:
  91. reserved: true
  92. cluster_permissions:
  93. - 'cluster:admin/opendistro/reports/definition/create'
  94. - 'cluster:admin/opendistro/reports/definition/update'
  95. - 'cluster:admin/opendistro/reports/definition/on_demand'
  96. - 'cluster:admin/opendistro/reports/definition/delete'
  97. - 'cluster:admin/opendistro/reports/definition/get'
  98. - 'cluster:admin/opendistro/reports/definition/list'
  99. - 'cluster:admin/opendistro/reports/instance/list'
  100. - 'cluster:admin/opendistro/reports/instance/get'
  101. - 'cluster:admin/opendistro/reports/menu/download'
  102. # Allows users to use all asynchronous-search functionality
  103. asynchronous_search_full_access:
  104. reserved: true
  105. cluster_permissions:
  106. - 'cluster:admin/opendistro/asynchronous_search/*'
  107. index_permissions:
  108. - index_patterns:
  109. - '*'
  110. allowed_actions:
  111. - 'indices:data/read/search*'
  112. # Allows users to read stored asynchronous-search results
  113. asynchronous_search_read_access:
  114. reserved: true
  115. cluster_permissions:
  116. - 'cluster:admin/opendistro/asynchronous_search/get'
  117. wazuh_ui_user:
  118. reserved: true
  119. hidden: false
  120. cluster_permissions: []
  121. index_permissions:
  122. - index_patterns:
  123. - "wazuh-*"
  124. dls: ""
  125. fls: []
  126. masked_fields: []
  127. allowed_actions:
  128. - "read"
  129. tenant_permissions: []
  130. static: false
  131. wazuh_ui_admin:
  132. reserved: true
  133. hidden: false
  134. cluster_permissions: []
  135. index_permissions:
  136. - index_patterns:
  137. - "wazuh-*"
  138. dls: ""
  139. fls: []
  140. masked_fields: []
  141. allowed_actions:
  142. - "read"
  143. - "delete"
  144. - "manage"
  145. - "index"
  146. tenant_permissions: []
  147. static: false
  148. # ISM API permissions role
  149. manage_ism:
  150. reserved: true
  151. hidden: false
  152. cluster_permissions:
  153. - "manage_ism"
  154. static: false