v1

latestOpenAPI 3.0.02026-08-064311,0881.3 MB
roleManagement

Get a role.

Get a role with the given identifier in the organization.

get/v1/roles/{id}

Path parameters

idstring required

Identifier of the role to fetch.

Response

Role object that was requested.

namestring required

Name of the role.

descriptionstring

Description of the role.

filterPredicatestring

A search filter to restrict access to specific logs. The filter is silently added to the beginning of each query a user runs. For example, using '!_sourceCategory=billing' as a filter predicate will prevent users assigned to the role from viewing logs from the source category named 'billing'.

usersstring[]

List of user identifiers to assign the role to.

capabilitiesstring[]

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • manageIndexes
  • manageDataStreams
  • viewParsers
  • viewDataStreams
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • ipWhitelisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist
  • shareDashboardWhitelist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse
  • cseViewAutomations
  • cseManageContextActions
  • cseViewNetworkBlocks
  • cseManageInsightTags
  • cseViewRules
  • cseViewThreatIntelligence
  • cseCommentOnInsights
  • cseViewEntityGroups
  • cseManageEntityConfiguration
  • cseManageNetworkBlocks
  • cseManageMatchLists
  • cseViewCustomInsights
  • cseManageActions
  • cseManageAutomations
  • cseManageMappings
  • cseManageThreatIntelligence
  • cseViewActions
  • cseCreateInsights
  • cseManageTagSchemas
  • cseInvokeInsights
  • cseManageCustomEntityType
  • cseViewTagSchemas
  • cseDeleteInsights
  • cseManageCustomInsights
  • cseViewFileAnalysis
  • cseManageFileAnalysis
  • cseManageEntityCriticality
  • cseViewEntityCriticality
  • cseViewEntity
  • cseManageCustomInsightStatuses
  • cseViewContextActions
  • cseViewMappings
  • cseViewCustomEntityType
  • cseManageEntityGroups
  • cseViewCustomInsightStatuses
  • cseViewEnrichments
  • cseManageInsightSignals
  • cseManageRules
  • cseManageArtifacts
  • cseViewMatchLists
  • cseManageInsightPolicy
  • cseManageEnrichments
  • cseViewEntityConfiguration
  • cseManageEntity
  • cseExecuteAutomations
  • cseManageSuppressedEntities
  • cseManageInsightStatus
  • cseManageInsightAssignee
  • cseManageFavoriteFields
  • cseViewSuppressedEntities

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
  • viewMutingSchedules
  • manageMutingSchedules
  • adminMonitorsV2

SLO

  • viewSlos
  • manageSlos

CloudSoar

  • cloudSoarPlaybooksAccess
  • cloudSoarNotificationConfigure
  • cloudSoarReportAll
  • cloudSoarIncidentTriageAccess
  • cloudSoarIncidentTaskView
  • cloudSoarIncidentChangeOwnership
  • cloudSoarIncidentNotesEdit
  • cloudSoarAPIEmailEdit
  • cloudSoarIncidentTemplatesAccess
  • cloudSoarIncidentPlaybooksManage
  • cloudSoarGeneralConfigure
  • cloudSoarEntitiesAccess
  • cloudSoarEntitiesBulkPhysicalDelete
  • cloudSoarIncidentAttachmentsAccess
  • cloudSoarAppCentralAccess
  • cloudSoarBridgeMonitoringAccess
  • viewCloudSoar
  • cloudSoarIncidentView
  • cloudSoarObservabilityAccess
  • cloudSoarAPIEmailRead
  • cloudSoarAppCentralExport
  • cloudSoarWidgetsAll
  • cloudSoarIncidentTaskReassign
  • cloudSoarIntegrationsAccess
  • cloudSoarCustomizationIncidentLabels
  • cloudSoarAutomationRulesConfigure
  • cloudSoarIncidentTaskAccessAll
  • cloudSoarAuditAndInformationConfigureAuditTrail
  • cloudSoarIncidentTriageEdit
  • cloudSoarIncidentEdit
  • cloudSoarNotificationTriage
  • cloudSoarIncidentTriageBulkPhysicalDelete
  • cloudSoarIncidentNotesAccess
  • cloudSoarAPIUse
  • cloudSoarIncidentPlaybooksEdit
  • cloudSoarDashboardAll
  • cloudSoarEntitiesManage
  • cloudSoarIncidentTemplatesConfigure
  • cloudSoarIncidentTriageAccessAll
  • cloudSoarPlaybooksConfigure
  • cloudSoarIncidentAccessAll
  • cloudSoarCustomizationLogo
  • cloudSoarIncidentTaskAccess
  • cloudSoarIncidentTriageView
  • cloudSoarIntegrationsConfigure
  • cloudSoarIncidentManageInvestigators
  • cloudSoarIncidentAccess
  • cloudSoarAuditAndInformationLicenseInformation
  • cloudSoarIncidentBulkOperations
  • cloudSoarCustomizationFields
  • cloudSoarIncidentTaskEdit
  • cloudSoarDashboardAccess
  • cloudSoarIncidentAttachmentsEdit
  • cloudSoarIncidentFoldersEdit
  • cloudSoarUserManagementGroups
  • cloudSoarIncidentPlaybooksAccess
  • cloudSoarIncidentWarRoomUse
  • cloudSoarReportAccess
  • cloudSoarAuditAndInformationAuditTrail
  • cloudSoarAutomationRulesAccess
  • cloudSoarIncidentTriageChangeOwnership
  • cloudSoarObservabilityManagement
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

createdAtstring date-time required

Creation timestamp in UTC in RFC3339 format.

createdBystring required

Identifier of the user who created the resource.

modifiedAtstring date-time required

Last modification timestamp in UTC.

modifiedBystring required

Identifier of the user who last modified the resource.

idstring required

Unique identifier for the role.

systemDefinedboolean

Role is system or user defined.

Example response

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "filterPredicate": "!_sourceCategory=billing",
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ],
  "createdAt": "2018-10-16T09:10:00Z",
  "createdBy": "0000000006743FDD",
  "modifiedAt": "2018-10-16T09:10:00Z",
  "modifiedBy": "0000000006743FE8",
  "id": "0000000000E20FE3"
}