v1

latestOpenAPI 3.0.02026-08-064311,0881.3 MB
roleManagementV2

Update a role.

Update an existing role in the organization.

put/v2/roles/{id}

Path parameters

idstring required

Identifier of the role to update.

Request body

namestring required

Name of the role.

descriptionstring required

Description of the role.

logAnalyticsFilterstring required

A search filter which would be applied on partitions which belong to Log Analytics product area.

auditDataFilterstring required

A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).

securityDataFilterstring required

A search filter which would be applied on partitions which belong to Security Data product area.

selectionTypestring required

Describes the Permission Construct for the list of views in "selectedViews" parameter.

Valid Values are :

  • All selectionType would allow access to all views in the org.
  • Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter.
  • Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter.
usersstring[] required

List of user identifiers to assign the role to.

capabilitiesstring[] required

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

Example request

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "logAnalyticsFilter": "!_sourceCategory=collector",
  "auditDataFilter": "info",
  "securityDataFilter": "error",
  "selectionType": "All",
  "selectedViews": [
    {
      "viewName": "auditData"
    }
  ],
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ]
}

Response

The user was successfully modified.

namestring required

Name of the role.

descriptionstring

Description of the role.

logAnalyticsFilterstring

A search filter which would be applied on partitions which belong to Log Analytics product area.

auditDataFilterstring

A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).

securityDataFilterstring

A search filter which would be applied on partitions which belong to Security Data product area.

selectionTypestring

Describes the Permission Construct for the list of views in "selectedViews" parameter.

Valid Values are :

  • All selectionType would allow access to all views in the org.
  • Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter.
  • Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter.
usersstring[]

List of user identifiers to assign the role to.

capabilitiesstring[]

List of capabilities associated with this role. Valid values are

Data Management

  • viewCollectors
  • manageCollectors
  • manageBudgets
  • manageDataVolumeFeed
  • viewFieldExtraction
  • manageFieldExtractionRules
  • manageS3DataForwarding
  • manageContent
  • manageApps
  • dataVolumeIndex
  • manageConnections
  • viewScheduledViews
  • manageScheduledViews
  • viewPartitions
  • managePartitions
  • viewFields
  • manageFields
  • viewAccountOverview
  • manageTokens
  • downloadSearchResults
  • manageIndexes
  • manageDataStreams
  • viewParsers
  • viewDataStreams
  • viewPipelines
  • managePipelines

Entity management

  • manageEntityTypeConfig

Metrics

  • metricsTransformation
  • metricsExtraction
  • metricsRules

Security

  • managePasswordPolicy
  • ipAllowlisting
  • ipWhitelisting
  • createAccessKeys
  • manageAccessKeys
  • manageSupportAccountAccess
  • manageAuditDataFeed
  • manageSaml
  • shareDashboardOutsideOrg
  • manageOrgSettings
  • changeDataAccessLevel

Dashboards

  • shareDashboardWorld
  • shareDashboardAllowlist
  • shareDashboardWhitelist

UserManagement

  • manageUsersAndRoles

Observability

  • searchAuditIndex
  • auditEventIndex

Cloud SIEM Enterprise

  • viewCse
  • cseViewAutomations
  • cseManageContextActions
  • cseViewNetworkBlocks
  • cseManageInsightTags
  • cseViewRules
  • cseViewThreatIntelligence
  • cseCommentOnInsights
  • cseViewEntityGroups
  • cseManageEntityConfiguration
  • cseManageNetworkBlocks
  • cseManageMatchLists
  • cseViewCustomInsights
  • cseManageActions
  • cseManageAutomations
  • cseManageMappings
  • cseManageThreatIntelligence
  • cseViewActions
  • cseCreateInsights
  • cseManageTagSchemas
  • cseInvokeInsights
  • cseManageCustomEntityType
  • cseViewTagSchemas
  • cseDeleteInsights
  • cseManageCustomInsights
  • cseViewFileAnalysis
  • cseManageFileAnalysis
  • cseManageEntityCriticality
  • cseViewEntityCriticality
  • cseViewEntity
  • cseManageCustomInsightStatuses
  • cseViewContextActions
  • cseViewMappings
  • cseViewCustomEntityType
  • cseManageEntityGroups
  • cseViewCustomInsightStatuses
  • cseViewEnrichments
  • cseManageInsightSignals
  • cseManageRules
  • cseManageArtifacts
  • cseViewMatchLists
  • cseManageInsightPolicy
  • cseManageEnrichments
  • cseViewEntityConfiguration
  • cseManageEntity
  • cseExecuteAutomations
  • cseManageSuppressedEntities
  • cseManageInsightStatus
  • cseManageInsightAssignee
  • cseManageFavoriteFields
  • cseViewSuppressedEntities

Alerting

  • viewMonitorsV2
  • manageMonitorsV2
  • viewAlerts
  • viewMutingSchedules
  • manageMutingSchedules
  • adminMonitorsV2

SLO

  • viewSlos
  • manageSlos

CloudSoar

  • cloudSoarPlaybooksAccess
  • cloudSoarNotificationConfigure
  • cloudSoarReportAll
  • cloudSoarIncidentTriageAccess
  • cloudSoarIncidentTaskView
  • cloudSoarIncidentChangeOwnership
  • cloudSoarIncidentNotesEdit
  • cloudSoarAPIEmailEdit
  • cloudSoarIncidentTemplatesAccess
  • cloudSoarIncidentPlaybooksManage
  • cloudSoarGeneralConfigure
  • cloudSoarEntitiesAccess
  • cloudSoarEntitiesBulkPhysicalDelete
  • cloudSoarIncidentAttachmentsAccess
  • cloudSoarAppCentralAccess
  • cloudSoarBridgeMonitoringAccess
  • viewCloudSoar
  • cloudSoarIncidentView
  • cloudSoarObservabilityAccess
  • cloudSoarAPIEmailRead
  • cloudSoarAppCentralExport
  • cloudSoarWidgetsAll
  • cloudSoarIncidentTaskReassign
  • cloudSoarIntegrationsAccess
  • cloudSoarCustomizationIncidentLabels
  • cloudSoarAutomationRulesConfigure
  • cloudSoarIncidentTaskAccessAll
  • cloudSoarAuditAndInformationConfigureAuditTrail
  • cloudSoarIncidentTriageEdit
  • cloudSoarIncidentEdit
  • cloudSoarNotificationTriage
  • cloudSoarIncidentTriageBulkPhysicalDelete
  • cloudSoarIncidentNotesAccess
  • cloudSoarAPIUse
  • cloudSoarIncidentPlaybooksEdit
  • cloudSoarDashboardAll
  • cloudSoarEntitiesManage
  • cloudSoarIncidentTemplatesConfigure
  • cloudSoarIncidentTriageAccessAll
  • cloudSoarPlaybooksConfigure
  • cloudSoarIncidentAccessAll
  • cloudSoarCustomizationLogo
  • cloudSoarIncidentTaskAccess
  • cloudSoarIncidentTriageView
  • cloudSoarIntegrationsConfigure
  • cloudSoarIncidentManageInvestigators
  • cloudSoarIncidentAccess
  • cloudSoarAuditAndInformationLicenseInformation
  • cloudSoarIncidentBulkOperations
  • cloudSoarCustomizationFields
  • cloudSoarIncidentTaskEdit
  • cloudSoarDashboardAccess
  • cloudSoarIncidentAttachmentsEdit
  • cloudSoarIncidentFoldersEdit
  • cloudSoarUserManagementGroups
  • cloudSoarIncidentPlaybooksAccess
  • cloudSoarIncidentWarRoomUse
  • cloudSoarReportAccess
  • cloudSoarAuditAndInformationAuditTrail
  • cloudSoarAutomationRulesAccess
  • cloudSoarIncidentTriageChangeOwnership
  • cloudSoarObservabilityManagement
autofillDependenciesboolean

Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.

createdAtstring date-time required

Creation timestamp in UTC in RFC3339 format.

createdBystring required

Identifier of the user who created the resource.

modifiedAtstring date-time required

Last modification timestamp in UTC.

modifiedBystring required

Identifier of the user who last modified the resource.

idstring required

Unique identifier for the role.

systemDefinedboolean

Role is system or user defined.

Example response

{
  "name": "DataAdmin",
  "description": "Manage data of the org.",
  "logAnalyticsFilter": "!_sourceCategory=collector",
  "auditDataFilter": "info",
  "securityDataFilter": "error",
  "selectionType": "All",
  "selectedViews": [
    {
      "viewName": "auditData"
    }
  ],
  "users": [
    "0000000006743FE0",
    "0000000005FCE0EE"
  ],
  "capabilities": [
    "manageContent",
    "manageDataVolumeFeed",
    "manageFieldExtractionRules",
    "manageS3DataForwarding"
  ],
  "createdAt": "2018-10-16T09:10:00Z",
  "createdBy": "0000000006743FDD",
  "modifiedAt": "2018-10-16T09:10:00Z",
  "modifiedBy": "0000000006743FE8",
  "id": "0000000000E20FE3"
}