Skip to main content

Role Capabilities

You can assign any of the following capabilities when you create roles.

Data Management

CapabilityDescription
Manage connectionsManage the connections that allow you to send alerts to other tools.
Manage CollectorsInstall and manage installed and hosted Collectors and Sources. Manage permission automatically includes view permission.
Manage Ingest BudgetsManage ingest budgets. Enabling this will automatically enable the Manage Collectors capability. The Manage Collectors capability on its own permits the re-assignment of budgets to different Collectors, but not creating or deleting them.
Manage data volume feedEnable and manage the data volume index for your account to avoid using On-Demand Capacity, and to determine when you need to upgrade your account.
View CollectorsView and Collectors and Sources that have already been installed or added.
View fieldsView fields, which are custom metadata fields you can assign to logs.
Manage fieldsManage fields, which are custom metadata fields you can assign to logs. Note that if you grant a role the Manage Fields capability, users with that role will also have the View Fields and View field extraction rules capabilities.
View field extraction rulesView field extraction rules, which speed the search process by automatically parsing fields as log messages are ingested.
Manage field extraction rulesManage field extractions, which speed the search process by automatically parsing fields as log messages are ingested. Note that if you grant a role the Manage field extraction rules capability, users with that role will also have the Manage Fields, View Fields, and View field extraction rules capabilities.
View PartitionsView Partitions.
Manage PartitionsView, create, edit, and delete Partitions. Note that if you grant a role the Manage Partitions capability, users with that role will also have View Partitions and Manage S3 data forwarding capabilities.
View Scheduled ViewsView Scheduled Views.
Manage Scheduled ViewsView, create, edit, and delete Scheduled Views. Note that if you grant a role the Manage Schedule View capability, users with that role will also have View Scheduled View capabilities.
Manage S3 data forwardingManage S3 data forwarding from Sumo Logic to an S3 bucket.
Manage ContentManage the content for your organization. This provides access to Admin Mode in the Library.
Manage TokensManage Installation Tokens.
View Account OverviewView the Account Overview page.
View ParsersView Parsers.

Metrics

CapabilityDescription
Manage Logs-to-MetricsCreate, edit, or delete Logs-to-Metrics rules. 
Manage Metrics Transformation RulesCreate, edit, or delete Metrics Transformation rules
Manage Metric RulesCreate, edit, or delete Metric Rules.

Security

CapabilityDescription
Manage password policySet the password policy for your Sumo Logic account.
Allowlist IP addressesExplicitly grant access to specific IP addresses or address ranges.
Create access keysAllows users to create their own access keys on the Preferences page.
Manage access keysSet up, activate, deactivate, or delete access keys for your organization.
Manage support account accessEnable management of the Sumo Logic support account for your organization.
Manage audit data feed.Enable and manage the Audit Index, which provides information on the internal events that occur in your account associated with account management, user activity, and scheduled searches.
Manage SAMLProvision and manage SAML for single sign-on to your Sumo Logic accounts.
Manage Share dashboards outside of the organizationShare a dashboard with users who don't have access to Sumo Logic.
Manage organization settingsUsers with this capability can configure a concurrent user sessions limit and enable the Data Access Level for Shared Dashboards security policy.
Change Data Access Level Users with this capability can change the data access level of dashboards or scheduled searches to which they have edit or manage permission.

Dashboards

CapabilityDescription
Share dashboards with the allowlistShare dashboards in view-only mode with no login required. Viewers must be connecting from IP addresses specified in your service allowlist.
Share dashboards with the worldShare dashboards in view-only mode with no login required. Anyone with the URL can view the dashboard without logging in.

User Management

CapabilityDescription
Manage users and roles Access the web app pages to manage users and roles.

Alerts

CapabilityDescription
View Monitors View Monitors.
Manage Monitors Create, edit, share, and delete Monitors.
View AlertsView Alerts

Organizations

CapabilityDescription
View OrganizationsView the Organizations UI.
Create OrganizationsCreate and provision child organizations.
Change Credits AllocationChange the credits allocation for a child organization.
Create Trial OrganizationsCreate trial organizations. (For Sumo Logic Service Providers only.)
Upgrade Trial OrganizationsUpgrade trial organizations. (For Sumo Logic Service Providers only.)
Deactivate OrganizationsDeactivate trial organizations. (For Sumo Logic Service Providers only.)

Cloud SIEM Enterprise

Cloud SIEM Enterprise (CSE) capabilities only appear in the Roles UI if CSE has been enabled for your account.

CapabilityDescription
View Cloud SIEM EnterpriseUsers with a role that grants this capability will see a "Cloud SIEM Enterprise" link in the left-nav bar of the Sumo Logic UI. When a user clicks on the link, the CSE Heads-Up Display (HUD) will open.
Comment on InsightsAdd comments to Insights.
Create InsightsCreate Insights.
Delete InsightsDelete Insights.
Invoke Insights ActionsChoose and run an action from the Actions menu for an Insight.
Manage Insight AssigneeChange the user that is assigned to an Insight.
Manage Insights SignalsAdd Signals to Insights; remove Signals from Insights.
Manage Insight StatusChange the status of an Insight.
Manage Insight TagsAdd and delete tags assigned to Insights.
Manage RulesCreate, edit, and delete rules.
Manage Threat IntelligenceCreate, edit, and delete threat intelligence sources.
Manage Match ListsCreate, edit, and delete Match Lists.
Manage File AnalysisCreate, edit, and delete YARA rules.
Manage Custom InsightsCreate, edit, and delete custom Insights
Manage Network BlocksCreate, edit, and delete network blocks.
Manage Suppressed EntitiesSuppress and unsuppress Entities.
Manage MappingsCreate, edit, and delete log mappings.
Manage WorkflowCreate, edit, and delete Workflow statuses.
Manage Context ActionsCreate, edit, and delete Context Actions.
Manage ActionsCreate, edit, and delete the Actions. Actions are CSE notifications you can set up to occur automatically when certain state changes occur to Insights, sensors, or rules. Actions can also be invoked on-demand from an Insight in the CSE UI.
Manage EnrichmentsUpload Insight, Signal, and Entity enrichments using the CSE API.
Manage Entity NormalizationUpdate the configurations on CSE’s Domain Normatization page.
Manage Entity Criticalityntries 2880/2882 dependencies 59/1190Create, edit, and delete Entity Criticalities.
Manage Tag SchemasCreate, edit, and delete schema key tags, which can be attached to Insights, Signals, Entities, and Rules.
Manage Favorite FieldsAdd and remove favorite fields by clicking the star icon next to the fields in CSE Records.