v1

latestOpenAPI 3.0.02026-08-064311,0881.3 MB
roleManagementV2

Assign a role to a user.

Assign a role to a user in the organization.

put/v2/roles/{roleId}/users/{userId}

Path parameters

roleIdstring required

Identifier of the role to assign.

userIdstring required

Identifier of the user to assign the role to.

Response

Role was successfully assigned to the user.

namestring required

Name of the role.

descriptionstring

Description of the role.

logAnalyticsFilterstring

A search filter which would be applied on partitions which belong to Log Analytics product area.

auditDataFilterstring

A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).

securityDataFilterstring

A search filter which would be applied on partitions which belong to Security Data product area.

selectionTypestring

Describes the Permission Construct for the list of views in "selectedViews" parameter.

Valid Values are :

  • All selectionType would allow access to all views in the org.
  • Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter.
  • Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter.
usersstring[]

List of user identifiers to assign the role to.

capabilitiesstring[]

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • manageIndexes
  • manageDataStreams
  • viewParsers
  • viewDataStreams
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • ipWhitelisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist
  • shareDashboardWhitelist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse
  • cseViewAutomations
  • cseManageContextActions
  • cseViewNetworkBlocks
  • cseManageInsightTags
  • cseViewRules
  • cseViewThreatIntelligence
  • cseCommentOnInsights
  • cseViewEntityGroups
  • cseManageEntityConfiguration
  • cseManageNetworkBlocks
  • cseManageMatchLists
  • cseViewCustomInsights
  • cseManageActions
  • cseManageAutomations
  • cseManageMappings
  • cseManageThreatIntelligence
  • cseViewActions
  • cseCreateInsights
  • cseManageTagSchemas
  • cseInvokeInsights
  • cseManageCustomEntityType
  • cseViewTagSchemas
  • cseDeleteInsights
  • cseManageCustomInsights
  • cseViewFileAnalysis
  • cseManageFileAnalysis
  • cseManageEntityCriticality
  • cseViewEntityCriticality
  • cseViewEntity
  • cseManageCustomInsightStatuses
  • cseViewContextActions
  • cseViewMappings
  • cseViewCustomEntityType
  • cseManageEntityGroups
  • cseViewCustomInsightStatuses
  • cseViewEnrichments
  • cseManageInsightSignals
  • cseManageRules
  • cseManageArtifacts
  • cseViewMatchLists
  • cseManageInsightPolicy
  • cseManageEnrichments
  • cseViewEntityConfiguration
  • cseManageEntity
  • cseExecuteAutomations
  • cseManageSuppressedEntities
  • cseManageInsightStatus
  • cseManageInsightAssignee
  • cseManageFavoriteFields
  • cseViewSuppressedEntities

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
  • viewMutingSchedules
  • manageMutingSchedules
  • adminMonitorsV2

SLO

  • viewSlos
  • manageSlos

CloudSoar

  • cloudSoarPlaybooksAccess
  • cloudSoarNotificationConfigure
  • cloudSoarReportAll
  • cloudSoarIncidentTriageAccess
  • cloudSoarIncidentTaskView
  • cloudSoarIncidentChangeOwnership
  • cloudSoarIncidentNotesEdit
  • cloudSoarAPIEmailEdit
  • cloudSoarIncidentTemplatesAccess
  • cloudSoarIncidentPlaybooksManage
  • cloudSoarGeneralConfigure
  • cloudSoarEntitiesAccess
  • cloudSoarEntitiesBulkPhysicalDelete
  • cloudSoarIncidentAttachmentsAccess
  • cloudSoarAppCentralAccess
  • cloudSoarBridgeMonitoringAccess
  • viewCloudSoar
  • cloudSoarIncidentView
  • cloudSoarObservabilityAccess
  • cloudSoarAPIEmailRead
  • cloudSoarAppCentralExport
  • cloudSoarWidgetsAll
  • cloudSoarIncidentTaskReassign
  • cloudSoarIntegrationsAccess
  • cloudSoarCustomizationIncidentLabels
  • cloudSoarAutomationRulesConfigure
  • cloudSoarIncidentTaskAccessAll
  • cloudSoarAuditAndInformationConfigureAuditTrail
  • cloudSoarIncidentTriageEdit
  • cloudSoarIncidentEdit
  • cloudSoarNotificationTriage
  • cloudSoarIncidentTriageBulkPhysicalDelete
  • cloudSoarIncidentNotesAccess
  • cloudSoarAPIUse
  • cloudSoarIncidentPlaybooksEdit
  • cloudSoarDashboardAll
  • cloudSoarEntitiesManage
  • cloudSoarIncidentTemplatesConfigure
  • cloudSoarIncidentTriageAccessAll
  • cloudSoarPlaybooksConfigure
  • cloudSoarIncidentAccessAll
  • cloudSoarCustomizationLogo
  • cloudSoarIncidentTaskAccess
  • cloudSoarIncidentTriageView
  • cloudSoarIntegrationsConfigure
  • cloudSoarIncidentManageInvestigators
  • cloudSoarIncidentAccess
  • cloudSoarAuditAndInformationLicenseInformation
  • cloudSoarIncidentBulkOperations
  • cloudSoarCustomizationFields
  • cloudSoarIncidentTaskEdit
  • cloudSoarDashboardAccess
  • cloudSoarIncidentAttachmentsEdit
  • cloudSoarIncidentFoldersEdit
  • cloudSoarUserManagementGroups
  • cloudSoarIncidentPlaybooksAccess
  • cloudSoarIncidentWarRoomUse
  • cloudSoarReportAccess
  • cloudSoarAuditAndInformationAuditTrail
  • cloudSoarAutomationRulesAccess
  • cloudSoarIncidentTriageChangeOwnership
  • cloudSoarObservabilityManagement
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

createdAtstring date-time required

Creation timestamp in UTC in RFC3339 format.

createdBystring required

Identifier of the user who created the resource.

modifiedAtstring date-time required

Last modification timestamp in UTC.

modifiedBystring required

Identifier of the user who last modified the resource.

idstring required

Unique identifier for the role.

systemDefinedboolean

Role is system or user defined.

Example response

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "logAnalyticsFilter": "!_sourceCategory=collector",
  "auditDataFilter": "info",
  "securityDataFilter": "error",
  "selectionType": "All",
  "selectedViews": [
    {
      "viewName": "auditData"
    }
  ],
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ],
  "createdAt": "2018-10-16T09:10:00Z",
  "createdBy": "0000000006743FDD",
  "modifiedAt": "2018-10-16T09:10:00Z",
  "modifiedBy": "0000000006743FE8",
  "id": "0000000000E20FE3"
}