Open for Voting

Account Limitations in LEM

We would like a similar ability that is already provided in Orion with the account limitations.  Right now, you can limit an account to basically read-only, but you have no control over the devices that that account can see events from.  Use case scenario: You have a server team and a network team.  You server team doesn't really want to see the network equipment logs and vice versa.

Thanks,

Chrystal Taylor

http://www.loop1systems.com

  • From a MSP viewpoint, the ability to provide delegated access to view/manage nodes and events for specific domains would be marvellous!

  • Separation of Duty as well as restricting access to certain log data depending on content would also be good business cases for this.

  • FormerMember
    FormerMember

    This would be a nice feature to have in principal, but it has some nasty side effects when you look at it from a higher level. The implementation of this would need to ensure that when it comes to creating rules, the correlation engine is not impacted by view limitations, as some rules will correlate a chain of events from different sources to trigger an alert, of which could be from servers and network devices.

    Also, when it comes to SIEM, visibility of all events captured should be key, as hiding clues from an analyst conducting a forensic investigation is only going to bite you in the behind when you need to rely on spotting the trends and anomalies within your network and server events logged in your SIEM solution.