Attaching error and configuration
a read-only user can analyse already created rule trace:
Troubleshooting > Rule tracing files > click on a rule tracing file > click on "Analyze" button - the rule trace will open in the rule tracing central
You can pre-create rule traces as admin or by using "Enable rule tracing" event, and let a read-only user to view/analyze it.
How to create a rule trace using "Enable rule tracing" event? If you know conditions that you want that the read-only user is able to analyze, create a rule with this conditions and a "Enable rule tracing" event:
Criteria: Client.IP equals 10.20.30.40 AND URL.Host equals example.com AND .....
Event: Enable Rule Tracing
another option is to create two roles: read-only and rule-tracing-only. These should be mapped to different AD-users. The user can use one account to login as a read-only user and other account to open rule tracing in an incognito browser window.
I was equally frustrated when i tried to create a support/servicedesk role. I've found two solutions
1) Create a role that can only access the Rule Tracing section but not the ruleset or lists, and then remove the read-only flag from that user. This will effectively limit access to "read-only" portions of the UI. It's quick and easy to configure, with the downside that it removes some transparency.
2) Alternatively, make sure all Rulesets and Lists are configured to provide read-only access to the role you created in 1), then give it access to Rulesets and Lists. This will also be effectively read-only. At least in my environment, when i create a new top-level ruleset, this role is automatically added to the read-only permission, so there's at least that. For lists that is unfortunately not the case, so this will be a manual task to keep them locked down. Permissions are unfortunately not exposed via the API either
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:
TrellixSkyhigh Security | Support Trellix.com SkyhighSecurity.com