cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Rule tracing central for ReadOnly users

Is there possibility to allow use Rule Tracing Central for users with RO permissions? We have AD group users which we prepared with ReadOnly permissions (Rule tracing option is also marked) but when they try to run this tool they got alert that not enough permissions is granted.
4 Replies

Re: Rule tracing central for ReadOnly users

Attaching error and configuration

fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 5

Re: Rule tracing central for ReadOnly users

Hello @User60760125 

a read-only user can analyse already created rule trace:

Troubleshooting > Rule tracing files > click on a rule tracing file > click on "Analyze" button - the rule trace will open in the rule tracing central

You can pre-create rule traces as admin or by using "Enable rule tracing" event, and let a read-only user to view/analyze it.

How to create a rule trace using "Enable rule tracing" event? If you know conditions that you want that the read-only user is able to analyze, create a rule with this conditions and a "Enable rule tracing" event:

Criteria: Client.IP equals 10.20.30.40 AND URL.Host equals example.com AND .....

Action: Continue

Event: Enable Rule Tracing

Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo to help other community members.
MWG+Splunk=❤
fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 5

Re: Rule tracing central for ReadOnly users

Hello @User60760125 

another option is to create two roles: read-only and rule-tracing-only. These should be mapped to different AD-users. The user can use one account to login as a read-only user and other account to open rule tracing in an incognito browser window.

Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo to help other community members.
MWG+Splunk=❤

Re: Rule tracing central for ReadOnly users

I was equally frustrated when i tried to create a support/servicedesk role. I've found two solutions

1) Create a role that can only access the Rule Tracing section but not the ruleset or lists, and then remove the read-only flag from that user. This will effectively limit access to "read-only" portions of the UI. It's quick and easy to configure, with the downside that it removes some transparency.

2) Alternatively, make sure all Rulesets and Lists are configured to provide read-only access to the role you created in 1), then give it access to Rulesets and Lists. This will also be effectively read-only. At least in my environment, when i create a new top-level ruleset, this role is automatically added to the read-only permission, so there's at least that. For lists that is unfortunately not the case, so this will be a manual task to keep them locked down. Permissions are unfortunately not exposed via the API either

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community