v1

latestOpenAPI 3.0.02026-08-064311,0881.3 MB
roleManagementV2

Create a new role.

Create a new role in the organization.

post/v2/roles

Request body

namestring required

Name of the role.

descriptionstring

Description of the role.

logAnalyticsFilterstring

A search filter which would be applied on partitions which belong to Log Analytics product area.

auditDataFilterstring

A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).

securityDataFilterstring

A search filter which would be applied on partitions which belong to Security Data product area.

selectionTypestring

Describes the Permission Construct for the list of views in "selectedViews" parameter.

Valid Values are :

  • All selectionType would allow access to all views in the org.
  • Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter.
  • Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter.
usersstring[]

List of user identifiers to assign the role to.

capabilitiesstring[]

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • manageIndexes
  • manageDataStreams
  • viewParsers
  • viewDataStreams
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • ipWhitelisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist
  • shareDashboardWhitelist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse
  • cseViewAutomations
  • cseManageContextActions
  • cseViewNetworkBlocks
  • cseManageInsightTags
  • cseViewRules
  • cseViewThreatIntelligence
  • cseCommentOnInsights
  • cseViewEntityGroups
  • cseManageEntityConfiguration
  • cseManageNetworkBlocks
  • cseManageMatchLists
  • cseViewCustomInsights
  • cseManageActions
  • cseManageAutomations
  • cseManageMappings
  • cseManageThreatIntelligence
  • cseViewActions
  • cseCreateInsights
  • cseManageTagSchemas
  • cseInvokeInsights
  • cseManageCustomEntityType
  • cseViewTagSchemas
  • cseDeleteInsights
  • cseManageCustomInsights
  • cseViewFileAnalysis
  • cseManageFileAnalysis
  • cseManageEntityCriticality
  • cseViewEntityCriticality
  • cseViewEntity
  • cseManageCustomInsightStatuses
  • cseViewContextActions
  • cseViewMappings
  • cseViewCustomEntityType
  • cseManageEntityGroups
  • cseViewCustomInsightStatuses
  • cseViewEnrichments
  • cseManageInsightSignals
  • cseManageRules
  • cseManageArtifacts
  • cseViewMatchLists
  • cseManageInsightPolicy
  • cseManageEnrichments
  • cseViewEntityConfiguration
  • cseManageEntity
  • cseExecuteAutomations
  • cseManageSuppressedEntities
  • cseManageInsightStatus
  • cseManageInsightAssignee
  • cseManageFavoriteFields
  • cseViewSuppressedEntities

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
  • viewMutingSchedules
  • manageMutingSchedules
  • adminMonitorsV2

SLO

  • viewSlos
  • manageSlos

CloudSoar

  • cloudSoarPlaybooksAccess
  • cloudSoarNotificationConfigure
  • cloudSoarReportAll
  • cloudSoarIncidentTriageAccess
  • cloudSoarIncidentTaskView
  • cloudSoarIncidentChangeOwnership
  • cloudSoarIncidentNotesEdit
  • cloudSoarAPIEmailEdit
  • cloudSoarIncidentTemplatesAccess
  • cloudSoarIncidentPlaybooksManage
  • cloudSoarGeneralConfigure
  • cloudSoarEntitiesAccess
  • cloudSoarEntitiesBulkPhysicalDelete
  • cloudSoarIncidentAttachmentsAccess
  • cloudSoarAppCentralAccess
  • cloudSoarBridgeMonitoringAccess
  • viewCloudSoar
  • cloudSoarIncidentView
  • cloudSoarObservabilityAccess
  • cloudSoarAPIEmailRead
  • cloudSoarAppCentralExport
  • cloudSoarWidgetsAll
  • cloudSoarIncidentTaskReassign
  • cloudSoarIntegrationsAccess
  • cloudSoarCustomizationIncidentLabels
  • cloudSoarAutomationRulesConfigure
  • cloudSoarIncidentTaskAccessAll
  • cloudSoarAuditAndInformationConfigureAuditTrail
  • cloudSoarIncidentTriageEdit
  • cloudSoarIncidentEdit
  • cloudSoarNotificationTriage
  • cloudSoarIncidentTriageBulkPhysicalDelete
  • cloudSoarIncidentNotesAccess
  • cloudSoarAPIUse
  • cloudSoarIncidentPlaybooksEdit
  • cloudSoarDashboardAll
  • cloudSoarEntitiesManage
  • cloudSoarIncidentTemplatesConfigure
  • cloudSoarIncidentTriageAccessAll
  • cloudSoarPlaybooksConfigure
  • cloudSoarIncidentAccessAll
  • cloudSoarCustomizationLogo
  • cloudSoarIncidentTaskAccess
  • cloudSoarIncidentTriageView
  • cloudSoarIntegrationsConfigure
  • cloudSoarIncidentManageInvestigators
  • cloudSoarIncidentAccess
  • cloudSoarAuditAndInformationLicenseInformation
  • cloudSoarIncidentBulkOperations
  • cloudSoarCustomizationFields
  • cloudSoarIncidentTaskEdit
  • cloudSoarDashboardAccess
  • cloudSoarIncidentAttachmentsEdit
  • cloudSoarIncidentFoldersEdit
  • cloudSoarUserManagementGroups
  • cloudSoarIncidentPlaybooksAccess
  • cloudSoarIncidentWarRoomUse
  • cloudSoarReportAccess
  • cloudSoarAuditAndInformationAuditTrail
  • cloudSoarAutomationRulesAccess
  • cloudSoarIncidentTriageChangeOwnership
  • cloudSoarObservabilityManagement
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

Example request

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "logAnalyticsFilter": "!_sourceCategory=collector",
  "auditDataFilter": "info",
  "securityDataFilter": "error",
  "selectionType": "All",
  "selectedViews": [
    {
      "viewName": "auditData"
    }
  ],
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ]
}

Response

The role has been created.

namestring required

Name of the role.

descriptionstring

Description of the role.

logAnalyticsFilterstring

A search filter which would be applied on partitions which belong to Log Analytics product area.

auditDataFilterstring

A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).

securityDataFilterstring

A search filter which would be applied on partitions which belong to Security Data product area.

selectionTypestring

Describes the Permission Construct for the list of views in "selectedViews" parameter.

Valid Values are :

  • All selectionType would allow access to all views in the org.
  • Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter.
  • Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter.
usersstring[]

List of user identifiers to assign the role to.

capabilitiesstring[]

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • manageIndexes
  • manageDataStreams
  • viewParsers
  • viewDataStreams
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • ipWhitelisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist
  • shareDashboardWhitelist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse
  • cseViewAutomations
  • cseManageContextActions
  • cseViewNetworkBlocks
  • cseManageInsightTags
  • cseViewRules
  • cseViewThreatIntelligence
  • cseCommentOnInsights
  • cseViewEntityGroups
  • cseManageEntityConfiguration
  • cseManageNetworkBlocks
  • cseManageMatchLists
  • cseViewCustomInsights
  • cseManageActions
  • cseManageAutomations
  • cseManageMappings
  • cseManageThreatIntelligence
  • cseViewActions
  • cseCreateInsights
  • cseManageTagSchemas
  • cseInvokeInsights
  • cseManageCustomEntityType
  • cseViewTagSchemas
  • cseDeleteInsights
  • cseManageCustomInsights
  • cseViewFileAnalysis
  • cseManageFileAnalysis
  • cseManageEntityCriticality
  • cseViewEntityCriticality
  • cseViewEntity
  • cseManageCustomInsightStatuses
  • cseViewContextActions
  • cseViewMappings
  • cseViewCustomEntityType
  • cseManageEntityGroups
  • cseViewCustomInsightStatuses
  • cseViewEnrichments
  • cseManageInsightSignals
  • cseManageRules
  • cseManageArtifacts
  • cseViewMatchLists
  • cseManageInsightPolicy
  • cseManageEnrichments
  • cseViewEntityConfiguration
  • cseManageEntity
  • cseExecuteAutomations
  • cseManageSuppressedEntities
  • cseManageInsightStatus
  • cseManageInsightAssignee
  • cseManageFavoriteFields
  • cseViewSuppressedEntities

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
  • viewMutingSchedules
  • manageMutingSchedules
  • adminMonitorsV2

SLO

  • viewSlos
  • manageSlos

CloudSoar

  • cloudSoarPlaybooksAccess
  • cloudSoarNotificationConfigure
  • cloudSoarReportAll
  • cloudSoarIncidentTriageAccess
  • cloudSoarIncidentTaskView
  • cloudSoarIncidentChangeOwnership
  • cloudSoarIncidentNotesEdit
  • cloudSoarAPIEmailEdit
  • cloudSoarIncidentTemplatesAccess
  • cloudSoarIncidentPlaybooksManage
  • cloudSoarGeneralConfigure
  • cloudSoarEntitiesAccess
  • cloudSoarEntitiesBulkPhysicalDelete
  • cloudSoarIncidentAttachmentsAccess
  • cloudSoarAppCentralAccess
  • cloudSoarBridgeMonitoringAccess
  • viewCloudSoar
  • cloudSoarIncidentView
  • cloudSoarObservabilityAccess
  • cloudSoarAPIEmailRead
  • cloudSoarAppCentralExport
  • cloudSoarWidgetsAll
  • cloudSoarIncidentTaskReassign
  • cloudSoarIntegrationsAccess
  • cloudSoarCustomizationIncidentLabels
  • cloudSoarAutomationRulesConfigure
  • cloudSoarIncidentTaskAccessAll
  • cloudSoarAuditAndInformationConfigureAuditTrail
  • cloudSoarIncidentTriageEdit
  • cloudSoarIncidentEdit
  • cloudSoarNotificationTriage
  • cloudSoarIncidentTriageBulkPhysicalDelete
  • cloudSoarIncidentNotesAccess
  • cloudSoarAPIUse
  • cloudSoarIncidentPlaybooksEdit
  • cloudSoarDashboardAll
  • cloudSoarEntitiesManage
  • cloudSoarIncidentTemplatesConfigure
  • cloudSoarIncidentTriageAccessAll
  • cloudSoarPlaybooksConfigure
  • cloudSoarIncidentAccessAll
  • cloudSoarCustomizationLogo
  • cloudSoarIncidentTaskAccess
  • cloudSoarIncidentTriageView
  • cloudSoarIntegrationsConfigure
  • cloudSoarIncidentManageInvestigators
  • cloudSoarIncidentAccess
  • cloudSoarAuditAndInformationLicenseInformation
  • cloudSoarIncidentBulkOperations
  • cloudSoarCustomizationFields
  • cloudSoarIncidentTaskEdit
  • cloudSoarDashboardAccess
  • cloudSoarIncidentAttachmentsEdit
  • cloudSoarIncidentFoldersEdit
  • cloudSoarUserManagementGroups
  • cloudSoarIncidentPlaybooksAccess
  • cloudSoarIncidentWarRoomUse
  • cloudSoarReportAccess
  • cloudSoarAuditAndInformationAuditTrail
  • cloudSoarAutomationRulesAccess
  • cloudSoarIncidentTriageChangeOwnership
  • cloudSoarObservabilityManagement
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

createdAtstring date-time required

Creation timestamp in UTC in RFC3339 format.

createdBystring required

Identifier of the user who created the resource.

modifiedAtstring date-time required

Last modification timestamp in UTC.

modifiedBystring required

Identifier of the user who last modified the resource.

idstring required

Unique identifier for the role.

systemDefinedboolean

Role is system or user defined.

Example response

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "logAnalyticsFilter": "!_sourceCategory=collector",
  "auditDataFilter": "info",
  "securityDataFilter": "error",
  "selectionType": "All",
  "selectedViews": [
    {
      "viewName": "auditData"
    }
  ],
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ],
  "createdAt": "2018-10-16T09:10:00Z",
  "createdBy": "0000000006743FDD",
  "modifiedAt": "2018-10-16T09:10:00Z",
  "modifiedBy": "0000000006743FE8",
  "id": "0000000000E20FE3"
}