Skip to main content

permissions

Creates, updates, deletes, gets or lists a permissions resource.

Overview​

Namepermissions
TypeResource
Idsumologic.monitors.permissions

Fields​

The following fields are returned by SELECT queries:

The list of explicit permission statements for the monitor or folder.

NameDatatypeDescription
subject_idstringThe identifier that belongs to the subject type chosen above. For e.g. if the subjectType is set to role, subjectId should be the identifier of a role. Similarly, if the subjectType is org, the subjectId should be the identifier of the same org, which owns the resource target. (example: 0000000006743FDA) (wire: subjectId)
target_idstringThe identifier that belongs to the resource this permission assignment applies to. (example: 0000000006743FE2) (wire: targetId)
created_atstring (date-time)Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt)
created_bystringIdentifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy)
modified_atstring (date-time)Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt)
modified_bystringIdentifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy)
permissionsarrayList of permissions.
subject_typestringType of subject for the permission. Valid values are: role or org. (pattern: <code>^(role|org)$</code>, example: role, x-pattern-message: must be one of the following: role or org) (wire: subjectType)

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectid, regionList explicit permissions on monitor or folder in the monitors library.
setexecregion, permissionStatementDefinitionsSet permissions on monitor or folder in the monitors library.
revokeexecregion, permissionIdentifiersRevoke all permissions on monitor or folder in the monitors library.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
idstringIdentifier of the monitor or folder to list permissions.
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)

SELECT examples​

List explicit permissions on monitor or folder in the monitors library.

SELECT
subject_id,
target_id,
created_at,
created_by,
modified_at,
modified_by,
permissions,
subject_type
FROM sumologic.monitors.permissions
WHERE id = '{{ id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;

Lifecycle Methods​

EXEC variables use wire (API) names.

Set permissions on monitor or folder in the monitors library.

EXEC sumologic.monitors.permissions.set
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
@@json=
'{
"permissionStatementDefinitions": "{{ permissionStatementDefinitions }}"
}'
;