permissions
Creates, updates, deletes, gets or lists a permissions resource.
Overview​
| Name | permissions |
| Type | Resource |
| Id | sumologic.monitors.permissions |
Fields​
The following fields are returned by SELECT queries:
- list
The list of explicit permission statements for the monitor or folder.
| Name | Datatype | Description |
|---|---|---|
subject_id | string | The identifier that belongs to the subject type chosen above. For e.g. if the subjectType is set to role, subjectId should be the identifier of a role. Similarly, if the subjectType is org, the subjectId should be the identifier of the same org, which owns the resource target. (example: 0000000006743FDA) (wire: subjectId) |
target_id | string | The identifier that belongs to the resource this permission assignment applies to. (example: 0000000006743FE2) (wire: targetId) |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
permissions | array | List of permissions. |
subject_type | string | Type of subject for the permission. Valid values are: role or org. (pattern: <code>^(role|org)$</code>, example: role, x-pattern-message: must be one of the following: role or org) (wire: subjectType) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | id, region | List explicit permissions on monitor or folder in the monitors library. | |
set | exec | region, permissionStatementDefinitions | Set permissions on monitor or folder in the monitors library. | |
revoke | exec | region, permissionIdentifiers | Revoke all permissions on monitor or folder in the monitors library. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
id | string | Identifier of the monitor or folder to list permissions. |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
SELECT examples​
- list
List explicit permissions on monitor or folder in the monitors library.
SELECT
subject_id,
target_id,
created_at,
created_by,
modified_at,
modified_by,
permissions,
subject_type
FROM sumologic.monitors.permissions
WHERE id = '{{ id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;
Lifecycle Methods​
EXEC variables use wire (API) names.
- set
- revoke
Set permissions on monitor or folder in the monitors library.
EXEC sumologic.monitors.permissions.set
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
@@json=
'{
"permissionStatementDefinitions": "{{ permissionStatementDefinitions }}"
}'
;
Revoke all permissions on monitor or folder in the monitors library.
EXEC sumologic.monitors.permissions.revoke
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
@@json=
'{
"permissionIdentifiers": "{{ permissionIdentifiers }}"
}'
;