Skip to main content

CSE User Accounts and Roles

This topic has information about creating and managing user accounts and roles for CSE. CSE uses role-based access control (RBAC). An administrator controls access to capabilities by assigning capabilities or permissions to roles, and then assigning users to roles.  

The process and UI for setting users and roles depends on your CSE environment. 

  • If your CSE URL ends in sumologic.com, you’ll set up users and roles in the Sumo Logic platform UI. For instructions, see the following help topics:

    • Create and Manage Roles The Sumo Logic platform allows you to assign multiple roles to a user. So, you might consider creating CSE-specific roles for different CSE user types, separate from roles you may define for Sumo Logic platform functionality. The CSE-related capabilities you can assign to roles are listed in the Cloud SIEM Enterprise section of the Role Capabilities page. 

      :::note When you create roles in the Sumo Logic platform, you have the option to set up a role search filter that specifies what log data users with the role may access. If you take advantage of that feature, be sure not to restrict CSE users’ access to indexes that contain CSE Records. :::

    • Create and Edit Users

  • If your CSE URL ends in jask.ai, you’ll set up user accounts and roles in the CSE UI. Follow the instructions below.

Invite a user

These instructions apply if your CSE URL ends in jask.ai.

  1. Click the gear icon, and choose Accounts under Users
    accounts-link.png
  2. On the Accounts page, click Invite.
    invite-link.png
  3. The Invite Users popup appears.
    invite-users.png
  4. Emails. Enter one or more email addresses. If you enter more than one address, separate them by commas.  
  5. Role. Use the down-arrow to view a list of roles, and choose one. You can view the permissions associated with available roles on the Roles page. (Click the gear icon, and choose Roles under Users.) 
  6. Click Invite

The individuals you invite will be sent an email with a link to the CSE UI, like the one shown below.

invitation.png

When the invitee accesses the CSE UI, they’ll be prompted to select a CSE username and password.  

Create a role in CSE

A CSE role has a set of permissions associated with it. Users with that role have the permissions assigned to the role. 

To create a role:

  1. Click the gear icon, and choose Roles under Users
    roles-link.png

  2. The Roles page appears, and lists the roles that are already defined. There are two built-in roles that cannot be deleted or edited: Administrator and Analyst. The avatar for each user that has the role is shown―hover over it to see the user's name and username. 
    roles-page.png

  3. Click Create.

  4. The Create Role popup appears.

    create-role-popup.png

  5. Name. Enter a name for the role.

  6. Permissions. Checkmark each permission you want to assign to the role. For a description of each permission, see Role Permissions, below.

  7. Click Create.

Role Permissions

Insights/Signals

[TABLE]

Records

PermissionDescription
Manage Favorite FieldsAdd and remove favorite fields by clicking the star button next to the fields in CSE Records.

Content

PermissionDescription
Create RulesCreate Rules.
Delete RulesDelete Rules.
Edit RulesEdit Rules.
Manage Threat IntelligenceCreate, edit, and delete threat intelligence sources.
Manage Match ListsCreate, edit, and delete Match Lists.
Manage File AnalysisCreate, edit, and delete YARA rules.
Manage Custom InsightsCreate, edit, and delete custom Insights.
Manage Network BlocksCreate, edit, and delete network blocks.
Manage Suppressed EntitiesSuppress and unsuppress Entities.
Manage Suppressed ListsCreate, edit, and delete lists of Record field values the presence of which will cause Signals to be suppressed. 

Other

PermissionDescription
Access Audit LogsAllows access to audit logs using API (/api/v1/audit-logs API).
Receive Admin EmailsReceive account notifications when other users change their emails, passwords, API keys, and so on.
Use API KeyEnables use of CSE API.

Configuration > Incoming Data

PermissionDescription
Manage SensorsInstall, configure, and uninstall CSE Sensors.
Manage Log MappingsCreate, edit, and delete log mappings.

Configuration > Entities

PermissionDescription
Manage Domain NormalizationUpdate the configurations on CSE’s Domain Normalization page.
Manage Entity CriticalityCreate, edit, and delete Entity Criticalities

Configuration > Users

PermissionDescription
Manage Accounts/Invitations/TeamsAdd new CSE users, edit and remove existing CSE users.
Manage Roles/PermissionsCreate, edit, and manage CSE user roles.
Manage WorkflowCreate, edit, and delete Workflow statuses.

Configuration > Integrations

PermissionDescription
Manage Sumo Logic IntegrationsCreate, edit, and delete Sumo Logic ingest mappings.
Manage Context ActionsCreate, edit, and delete Context Actions.
Manage ActionsCreate, edit, and delete the Actions. Actions are CSE notifications you can set up to occur automatically when certain state changes occur to Insights, sensors, or rules. Actions can also be invoked on-demand from an Insight in the CSE UI.
Manage EnrichmentsUpload Insight, Signal, and Entity enrichments using the CSE API.