Skip to main content

roles_v2

Creates, updates, deletes, gets or lists a roles_v2 resource.

Overview​

Nameroles_v2
TypeResource
Idsumologic.roles.roles_v2

Fields​

The following fields are returned by SELECT queries:

Role object that was requested.

NameDatatypeDescription
idstringUnique identifier for the role. (example: 0000000000E20FE3)
namestringName of the role. (example: DataAdmin)
audit_data_filterstringA search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https:​//help.sumologic.com/docs/manage/security/audit-index/). (example: info) (wire: auditDataFilter)
autofill_dependenciesbooleanSet this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies. (wire: autofillDependencies)
capabilitiesarrayList of [capabilities](https:​//help.sumologic.com/Manage/Users-and-Roles/Manage-Roles/Role-Capabilities) associated with this role. Valid values are ### Data Management - viewCollectors - manageCollectors - manageBudgets - manageDataVolumeFeed - viewFieldExtraction - manageFieldExtractionRules - manageS3DataForwarding - manageContent - manageApps - dataVolumeIndex - manageConnections - viewScheduledViews - manageScheduledViews - viewPartitions - managePartitions - viewFields - manageFields - viewAccountOverview - manageTokens - downloadSearchResults - viewPipelines - managePipelines ### Entity management - manageEntityTypeConfig ### Metrics - metricsTransformation - metricsExtraction - metricsRules ### Security - managePasswordPolicy - ipAllowlisting - createAccessKeys - manageAccessKeys - manageSupportAccountAccess - manageAuditDataFeed - manageSaml - shareDashboardOutsideOrg - manageOrgSettings - changeDataAccessLevel ### Dashboards - shareDashboardWorld - shareDashboardAllowlist ### UserManagement - manageUsersAndRoles ### Observability - searchAuditIndex - auditEventIndex ### Cloud SIEM Enterprise - viewCse ### Alerting - viewMonitorsV2 - manageMonitorsV2 - viewAlerts
created_atstring (date-time)Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt)
created_bystringIdentifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy)
descriptionstringDescription of the role. (example: Manage data of the org.)
log_analytics_filterstringA search filter which would be applied on partitions which belong to Log Analytics product area. (example: !_sourceCategory=collector) (wire: logAnalyticsFilter)
modified_atstring (date-time)Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt)
modified_bystringIdentifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy)
security_data_filterstringA search filter which would be applied on partitions which belong to Security Data product area. (example: error) (wire: securityDataFilter)
selected_viewsarrayList of views which with specific view level filters in accordance to the selectionType chosen. (wire: selectedViews)
selection_typestringDescribes the Permission Construct for the list of views in "selectedViews" parameter. ### Valid Values are : - All selectionType would allow access to all views in the org. - Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter. - Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter. (example: All) (wire: selectionType)
system_definedbooleanRole is system or user defined. (wire: systemDefined)
usersarrayList of user identifiers to assign the role to.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectid, regionGet a role with the given identifier in the organization.
listselectregionlimit, token, sort_by, nameGet a list of all the roles in the organization. The response is paginated with a default limit of 100 roles per page.
createinsertregion, nameCreate a new role in the organization.
updateupdateid, region, audit_data_filter, capabilities, description, log_analytics_filter, name, security_data_filter, selected_views, selection_type, usersUpdate an existing role in the organization.
deletedeleteid, regionDelete a role with the given identifier from the organization.
assign_userexecroleId, userId, regionAssign a role to a user in the organization.
remove_userexecroleId, userId, regionRemove a role from a user in the organization.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
idstringIdentifier of the role to delete.
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)
roleIdstringIdentifier of the role to delete.
userIdstringIdentifier of the user to remove the role from.
limitinteger (int32)Limit the number of roles returned in the response. The number of roles returned may be less than the limit.
namestringOnly return roles matching the given name.
sort_bystringSort the list of roles by the name field. (wire: sortBy)
tokenstringContinuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. token is set to null when no more pages are left.

SELECT examples​

Get a role with the given identifier in the organization.

SELECT
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users
FROM sumologic.roles.roles_v2
WHERE id = '{{ id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;

INSERT examples​

Create a new role in the organization.

INSERT INTO sumologic.roles.roles_v2 (
name,
description,
log_analytics_filter,
audit_data_filter,
security_data_filter,
selection_type,
selected_views,
users,
capabilities,
autofill_dependencies,
region
)
SELECT
'{{ name }}' /* required */,
'{{ description }}',
'{{ log_analytics_filter }}',
'{{ audit_data_filter }}',
'{{ security_data_filter }}',
'{{ selection_type }}',
'{{ selected_views }}',
'{{ users }}',
'{{ capabilities }}',
{{ autofill_dependencies }},
'{{ region }}'
RETURNING
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users
;

UPDATE examples​

Update an existing role in the organization.

UPDATE sumologic.roles.roles_v2
SET
name = '{{ name }}',
description = '{{ description }}',
log_analytics_filter = '{{ log_analytics_filter }}',
audit_data_filter = '{{ audit_data_filter }}',
security_data_filter = '{{ security_data_filter }}',
selection_type = '{{ selection_type }}',
selected_views = '{{ selected_views }}',
users = '{{ users }}',
capabilities = '{{ capabilities }}',
autofill_dependencies = {{ autofill_dependencies }}
WHERE
id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND audit_data_filter = '{{ audit_data_filter }}' --required
AND capabilities = '{{ capabilities }}' --required
AND description = '{{ description }}' --required
AND log_analytics_filter = '{{ log_analytics_filter }}' --required
AND name = '{{ name }}' --required
AND security_data_filter = '{{ security_data_filter }}' --required
AND selected_views = '{{ selected_views }}' --required
AND selection_type = '{{ selection_type }}' --required
AND users = '{{ users }}' --required
RETURNING
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users;

DELETE examples​

Delete a role with the given identifier from the organization.

DELETE FROM sumologic.roles.roles_v2
WHERE id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;

Lifecycle Methods​

EXEC variables use wire (API) names.

Assign a role to a user in the organization.

EXEC sumologic.roles.roles_v2.assign_user
@roleId='{{ roleId }}' --required,
@userId='{{ userId }}' --required,
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;