Skip to content

Commit

Permalink
resets operator_users file to match production + risk score index. (#…
Browse files Browse the repository at this point in the history
  • Loading branch information
dhurley14 authored Oct 17, 2023
1 parent ad58290 commit f05d976
Show file tree
Hide file tree
Showing 2 changed files with 15 additions and 16 deletions.
16 changes: 1 addition & 15 deletions packages/kbn-es/src/serverless_resources/operator_users.yml
Original file line number Diff line number Diff line change
@@ -1,19 +1,5 @@
operator:
- usernames:
[
'elastic_serverless',
'system_indices_superuser',
't1_analyst',
't2_analyst',
't3_analyst',
'threat_intelligence_analyst',
'rule_author',
'soc_manager',
'detections_admin',
'platform_engineer',
'endpoint_operations_analyst',
'endpoint_policy_manager',
]
- usernames: ['elastic_serverless', 'system_indices_superuser']
realm_type: 'file'
auth_type: 'realm'
- usernames: ['elastic/kibana']
Expand Down
15 changes: 14 additions & 1 deletion packages/kbn-es/src/serverless_resources/roles.yml
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,7 @@ t1_analyst:
- metrics-endpoint.metadata_current_*
- ".fleet-agents*"
- ".fleet-actions*"
- "risk-score.risk-score-*"
privileges:
- read
applications:
Expand Down Expand Up @@ -157,6 +158,7 @@ t2_analyst:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- "risk-score.risk-score-*"
privileges:
- read
applications:
Expand Down Expand Up @@ -204,6 +206,7 @@ t3_analyst:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- "risk-score.risk-score-*"
privileges:
- read
applications:
Expand Down Expand Up @@ -256,6 +259,7 @@ threat_intelligence_analyst:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- "risk-score.risk-score-*"
privileges:
- read
applications:
Expand Down Expand Up @@ -307,6 +311,7 @@ rule_author:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- "risk-score.risk-score-*"
privileges:
- read
applications:
Expand Down Expand Up @@ -363,6 +368,7 @@ soc_manager:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- risk-score.risk-score-*
privileges:
- read
applications:
Expand Down Expand Up @@ -391,7 +397,7 @@ soc_manager:
resources: "*"

detections_admin:
cluster:
cluster: ["manage_index_templates", "manage_transform"]
indices:
- names:
- apm-*-transaction*
Expand All @@ -418,6 +424,10 @@ detections_admin:
- .fleet-actions*
privileges:
- read
- names:
- risk-score.risk-score-*
privileges:
- all
applications:
- application: "kibana-.kibana"
privileges:
Expand Down Expand Up @@ -450,6 +460,7 @@ platform_engineer:
- .siem-signals-*
- .preview.alerts-security*
- .internal.preview.alerts-security*
- risk-score.risk-score-*
privileges:
- all
applications:
Expand Down Expand Up @@ -482,6 +493,7 @@ endpoint_operations_analyst:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- risk-score.risk-score-*
privileges:
- read
- names:
Expand Down Expand Up @@ -537,6 +549,7 @@ endpoint_policy_manager:
- metrics-endpoint.metadata_current_*
- .fleet-agents*
- .fleet-actions*
- risk-score.risk-score-*
privileges:
- read
- names:
Expand Down

0 comments on commit f05d976

Please sign in to comment.