Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue 437: Maintenance permission #492

Merged
merged 8 commits into from
Feb 24, 2021
Merged

Conversation

narcher7
Copy link
Contributor

@narcher7 narcher7 commented Feb 5, 2021

No description provided.

@narcher7 narcher7 self-assigned this Feb 8, 2021
@spong
Copy link
Member

spong commented Feb 8, 2021

Referenced images will need to be updated as well:

@spong
Copy link
Member

spong commented Feb 8, 2021

So the intent behind elastic/kibana#87761 was to allow the creation of a user (role) that can change alert state (open/in-progress/closed), but not have the ability to create/edit rules. Can we create a third group like Access and use Detections for this role and call out this behavior? It'd essentially be what the newly updated Access and use Detections section (w/ maintenance) and a change of Kibana space privileges to Security Solution read, if I recall correctly.

@narcher7
Copy link
Contributor Author

Preview

@spong
Copy link
Member

spong commented Feb 23, 2021

There's a bit to un-pack here @Donnater @jmikell821, so please do reach out as I'm happy to pair on this one.

Notes:

[1] As of elastic/kibana#90895 the Saved Objects Management feature privilege is no longer necessary, and can be removed from both sections. This change is for 7.12, not 7.11

[2] For the Enable Detections section maintenance isn't necessary as the manage privilege will satisfy the same permissions.

@cla-checker-service
Copy link

cla-checker-service bot commented Feb 23, 2021

❌ Author of the following commits did not sign a Contributor Agreement:
5f8e162, 660ccfc

Please, read and sign the above mentioned agreement if you want to contribute to this project

@narcher7
Copy link
Contributor Author

narcher7 commented Feb 24, 2021

Preview

Copy link
Member

@spong spong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks for pairing on this one to get everything just right @Donnater, appreciate it! 🙂

@narcher7 narcher7 merged commit 7946b4c into master Feb 24, 2021
@narcher7 narcher7 deleted the Issue-437-maintenance-permission branch February 24, 2021 01:44
narcher7 added a commit to narcher7/security-docs that referenced this pull request Feb 24, 2021
* Issue elastic#437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
narcher7 added a commit to narcher7/security-docs that referenced this pull request Feb 24, 2021
* Issue elastic#437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
narcher7 added a commit to narcher7/security-docs that referenced this pull request Feb 24, 2021
* Issue elastic#437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
narcher7 added a commit that referenced this pull request Feb 24, 2021
* Issue #437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
narcher7 added a commit that referenced this pull request Feb 24, 2021
* Issue #437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
narcher7 added a commit that referenced this pull request Feb 24, 2021
* Issue #437: Add maintenance permission for SIEM index

* Rework detections section

* Add slight edits to the new section.

* Add a couple more grammar edits.

* Update docs/getting-started/detections-req.asciidoc

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

* Add back in accidental deletion

Co-authored-by: DonNateR <>
Co-authored-by: Garrett Spong <spong@users.noreply.github.com>

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants