roles_v2
Creates, updates, deletes, gets or lists a roles_v2 resource.
Overview​
| Name | roles_v2 |
| Type | Resource |
| Id | sumologic.roles.roles_v2 |
Fields​
The following fields are returned by SELECT queries:
- get
- list
Role object that was requested.
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier for the role. (example: 0000000000E20FE3) |
name | string | Name of the role. (example: DataAdmin) |
audit_data_filter | string | A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https:​//help.sumologic.com/docs/manage/security/audit-index/). (example: info) (wire: auditDataFilter) |
autofill_dependencies | boolean | Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies. (wire: autofillDependencies) |
capabilities | array | List of [capabilities](https:​//help.sumologic.com/Manage/Users-and-Roles/Manage-Roles/Role-Capabilities) associated with this role. Valid values are ### Data Management - viewCollectors - manageCollectors - manageBudgets - manageDataVolumeFeed - viewFieldExtraction - manageFieldExtractionRules - manageS3DataForwarding - manageContent - manageApps - dataVolumeIndex - manageConnections - viewScheduledViews - manageScheduledViews - viewPartitions - managePartitions - viewFields - manageFields - viewAccountOverview - manageTokens - downloadSearchResults - viewPipelines - managePipelines ### Entity management - manageEntityTypeConfig ### Metrics - metricsTransformation - metricsExtraction - metricsRules ### Security - managePasswordPolicy - ipAllowlisting - createAccessKeys - manageAccessKeys - manageSupportAccountAccess - manageAuditDataFeed - manageSaml - shareDashboardOutsideOrg - manageOrgSettings - changeDataAccessLevel ### Dashboards - shareDashboardWorld - shareDashboardAllowlist ### UserManagement - manageUsersAndRoles ### Observability - searchAuditIndex - auditEventIndex ### Cloud SIEM Enterprise - viewCse ### Alerting - viewMonitorsV2 - manageMonitorsV2 - viewAlerts |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
description | string | Description of the role. (example: Manage data of the org.) |
log_analytics_filter | string | A search filter which would be applied on partitions which belong to Log Analytics product area. (example: !_sourceCategory=collector) (wire: logAnalyticsFilter) |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
security_data_filter | string | A search filter which would be applied on partitions which belong to Security Data product area. (example: error) (wire: securityDataFilter) |
selected_views | array | List of views which with specific view level filters in accordance to the selectionType chosen. (wire: selectedViews) |
selection_type | string | Describes the Permission Construct for the list of views in "selectedViews" parameter. ### Valid Values are : - All selectionType would allow access to all views in the org. - Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter. - Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter. (example: All) (wire: selectionType) |
system_defined | boolean | Role is system or user defined. (wire: systemDefined) |
users | array | List of user identifiers to assign the role to. |
A paginated list of roles in the organization.
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier for the role. (example: 0000000000E20FE3) |
name | string | Name of the role. (example: DataAdmin) |
audit_data_filter | string | A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https:​//help.sumologic.com/docs/manage/security/audit-index/). (example: info) (wire: auditDataFilter) |
autofill_dependencies | boolean | Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies. (wire: autofillDependencies) |
capabilities | array | List of [capabilities](https:​//help.sumologic.com/Manage/Users-and-Roles/Manage-Roles/Role-Capabilities) associated with this role. Valid values are ### Data Management - viewCollectors - manageCollectors - manageBudgets - manageDataVolumeFeed - viewFieldExtraction - manageFieldExtractionRules - manageS3DataForwarding - manageContent - manageApps - dataVolumeIndex - manageConnections - viewScheduledViews - manageScheduledViews - viewPartitions - managePartitions - viewFields - manageFields - viewAccountOverview - manageTokens - downloadSearchResults - viewPipelines - managePipelines ### Entity management - manageEntityTypeConfig ### Metrics - metricsTransformation - metricsExtraction - metricsRules ### Security - managePasswordPolicy - ipAllowlisting - createAccessKeys - manageAccessKeys - manageSupportAccountAccess - manageAuditDataFeed - manageSaml - shareDashboardOutsideOrg - manageOrgSettings - changeDataAccessLevel ### Dashboards - shareDashboardWorld - shareDashboardAllowlist ### UserManagement - manageUsersAndRoles ### Observability - searchAuditIndex - auditEventIndex ### Cloud SIEM Enterprise - viewCse ### Alerting - viewMonitorsV2 - manageMonitorsV2 - viewAlerts |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
description | string | Description of the role. (example: Manage data of the org.) |
log_analytics_filter | string | A search filter which would be applied on partitions which belong to Log Analytics product area. (example: !_sourceCategory=collector) (wire: logAnalyticsFilter) |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
security_data_filter | string | A search filter which would be applied on partitions which belong to Security Data product area. (example: error) (wire: securityDataFilter) |
selected_views | array | List of views which with specific view level filters in accordance to the selectionType chosen. (wire: selectedViews) |
selection_type | string | Describes the Permission Construct for the list of views in "selectedViews" parameter. ### Valid Values are : - All selectionType would allow access to all views in the org. - Allow selectionType would allow access to specific views mentioned in "selectedViews" parameter. - Deny selectionType would deny access to specific views mentioned in "selectedViews" parameter. (example: All) (wire: selectionType) |
system_defined | boolean | Role is system or user defined. (wire: systemDefined) |
users | array | List of user identifiers to assign the role to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | id, region | Get a role with the given identifier in the organization. | |
list | select | region | limit, token, sort_by, name | Get a list of all the roles in the organization. The response is paginated with a default limit of 100 roles per page. |
create | insert | region, name | Create a new role in the organization. | |
update | update | id, region, audit_data_filter, capabilities, description, log_analytics_filter, name, security_data_filter, selected_views, selection_type, users | Update an existing role in the organization. | |
delete | delete | id, region | Delete a role with the given identifier from the organization. | |
assign_user | exec | roleId, userId, region | Assign a role to a user in the organization. | |
remove_user | exec | roleId, userId, region | Remove a role from a user in the organization. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
id | string | Identifier of the role to delete. |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
roleId | string | Identifier of the role to delete. |
userId | string | Identifier of the user to remove the role from. |
limit | integer (int32) | Limit the number of roles returned in the response. The number of roles returned may be less than the limit. |
name | string | Only return roles matching the given name. |
sort_by | string | Sort the list of roles by the name field. (wire: sortBy) |
token | string | Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. token is set to null when no more pages are left. |
SELECT examples​
- get
- list
Get a role with the given identifier in the organization.
SELECT
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users
FROM sumologic.roles.roles_v2
WHERE id = '{{ id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;
Get a list of all the roles in the organization. The response is paginated with a default limit of 100 roles per page.
SELECT
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users
FROM sumologic.roles.roles_v2
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND limit = '{{ limit }}'
AND token = '{{ token }}'
AND sort_by = '{{ sort_by }}'
AND name = '{{ name }}'
;
INSERT examples​
- create
- Manifest
Create a new role in the organization.
INSERT INTO sumologic.roles.roles_v2 (
name,
description,
log_analytics_filter,
audit_data_filter,
security_data_filter,
selection_type,
selected_views,
users,
capabilities,
autofill_dependencies,
region
)
SELECT
'{{ name }}' /* required */,
'{{ description }}',
'{{ log_analytics_filter }}',
'{{ audit_data_filter }}',
'{{ security_data_filter }}',
'{{ selection_type }}',
'{{ selected_views }}',
'{{ users }}',
'{{ capabilities }}',
{{ autofill_dependencies }},
'{{ region }}'
RETURNING
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users
;
# Description fields are for documentation purposes
- name: roles_v2
props:
- name: region
value: "{{ region }}"
description: Required parameter for the roles_v2 resource.
- name: name
value: "{{ name }}"
description: |
Name of the role.
- name: description
value: "{{ description }}"
description: |
Description of the role.
- name: log_analytics_filter
value: "{{ log_analytics_filter }}"
description: |
A search filter which would be applied on partitions which belong to Log Analytics product area.
- name: audit_data_filter
value: "{{ audit_data_filter }}"
description: |
A search filter which would be applied on partitions which belong to Audit Data product area. Help Doc : (https://help.sumologic.com/docs/manage/security/audit-index/).
- name: security_data_filter
value: "{{ security_data_filter }}"
description: |
A search filter which would be applied on partitions which belong to Security Data product area.
- name: selection_type
value: "{{ selection_type }}"
description: |
Describes the Permission Construct for the list of views in "selectedViews" parameter.
### Valid Values are :
- `All` selectionType would allow access to all views in the org.
- `Allow` selectionType would allow access to specific views mentioned in "selectedViews" parameter.
- `Deny` selectionType would deny access to specific views mentioned in "selectedViews" parameter.
- name: selected_views
description: |
List of views which with specific view level filters in accordance to the selectionType chosen.
value:
- viewName: "{{ viewName }}"
- name: users
value:
- "{{ users }}"
description: |
List of user identifiers to assign the role to.
- name: capabilities
value:
- "{{ capabilities }}"
description: |
List of [capabilities](https://help.sumologic.com/docs/manage/users-roles/roles/role-capabilities/) associated with this role. Valid values are
### Data Management
- viewCollectors
- manageCollectors
- manageBudgets
- manageDataVolumeFeed
- viewFieldExtraction
- manageFieldExtractionRules
- manageS3DataForwarding
- manageContent
- manageApps
- dataVolumeIndex
- manageConnections
- viewScheduledViews
- manageScheduledViews
- viewPartitions
- managePartitions
- viewFields
- manageFields
- viewAccountOverview
- manageTokens
- downloadSearchResults
- manageIndexes
- manageDataStreams
- viewParsers
- viewDataStreams
- viewPipelines
- managePipelines
### Entity management
- manageEntityTypeConfig
### Metrics
- metricsTransformation
- metricsExtraction
- metricsRules
### Security
- managePasswordPolicy
- ipAllowlisting
- ipWhitelisting
- createAccessKeys
- manageAccessKeys
- manageSupportAccountAccess
- manageAuditDataFeed
- manageSaml
- shareDashboardOutsideOrg
- manageOrgSettings
- changeDataAccessLevel
### Dashboards
- shareDashboardWorld
- shareDashboardAllowlist
- shareDashboardWhitelist
### UserManagement
- manageUsersAndRoles
### Observability
- searchAuditIndex
- auditEventIndex
### Cloud SIEM Enterprise
- viewCse
- cseViewAutomations
- cseManageContextActions
- cseViewNetworkBlocks
- cseManageInsightTags
- cseViewRules
- cseViewThreatIntelligence
- cseCommentOnInsights
- cseViewEntityGroups
- cseManageEntityConfiguration
- cseManageNetworkBlocks
- cseManageMatchLists
- cseViewCustomInsights
- cseManageActions
- cseManageAutomations
- cseManageMappings
- cseManageThreatIntelligence
- cseViewActions
- cseCreateInsights
- cseManageTagSchemas
- cseInvokeInsights
- cseManageCustomEntityType
- cseViewTagSchemas
- cseDeleteInsights
- cseManageCustomInsights
- cseViewFileAnalysis
- cseManageFileAnalysis
- cseManageEntityCriticality
- cseViewEntityCriticality
- cseViewEntity
- cseManageCustomInsightStatuses
- cseViewContextActions
- cseViewMappings
- cseViewCustomEntityType
- cseManageEntityGroups
- cseViewCustomInsightStatuses
- cseViewEnrichments
- cseManageInsightSignals
- cseManageRules
- cseManageArtifacts
- cseViewMatchLists
- cseManageInsightPolicy
- cseManageEnrichments
- cseViewEntityConfiguration
- cseManageEntity
- cseExecuteAutomations
- cseManageSuppressedEntities
- cseManageInsightStatus
- cseManageInsightAssignee
- cseManageFavoriteFields
- cseViewSuppressedEntities
### Alerting
- viewMonitorsV2
- manageMonitorsV2
- viewAlerts
- viewMutingSchedules
- manageMutingSchedules
- adminMonitorsV2
### SLO
- viewSlos
- manageSlos
### CloudSoar
- cloudSoarPlaybooksAccess
- cloudSoarNotificationConfigure
- cloudSoarReportAll
- cloudSoarIncidentTriageAccess
- cloudSoarIncidentTaskView
- cloudSoarIncidentChangeOwnership
- cloudSoarIncidentNotesEdit
- cloudSoarAPIEmailEdit
- cloudSoarIncidentTemplatesAccess
- cloudSoarIncidentPlaybooksManage
- cloudSoarGeneralConfigure
- cloudSoarEntitiesAccess
- cloudSoarEntitiesBulkPhysicalDelete
- cloudSoarIncidentAttachmentsAccess
- cloudSoarAppCentralAccess
- cloudSoarBridgeMonitoringAccess
- viewCloudSoar
- cloudSoarIncidentView
- cloudSoarObservabilityAccess
- cloudSoarAPIEmailRead
- cloudSoarAppCentralExport
- cloudSoarWidgetsAll
- cloudSoarIncidentTaskReassign
- cloudSoarIntegrationsAccess
- cloudSoarCustomizationIncidentLabels
- cloudSoarAutomationRulesConfigure
- cloudSoarIncidentTaskAccessAll
- cloudSoarAuditAndInformationConfigureAuditTrail
- cloudSoarIncidentTriageEdit
- cloudSoarIncidentEdit
- cloudSoarNotificationTriage
- cloudSoarIncidentTriageBulkPhysicalDelete
- cloudSoarIncidentNotesAccess
- cloudSoarAPIUse
- cloudSoarIncidentPlaybooksEdit
- cloudSoarDashboardAll
- cloudSoarEntitiesManage
- cloudSoarIncidentTemplatesConfigure
- cloudSoarIncidentTriageAccessAll
- cloudSoarPlaybooksConfigure
- cloudSoarIncidentAccessAll
- cloudSoarCustomizationLogo
- cloudSoarIncidentTaskAccess
- cloudSoarIncidentTriageView
- cloudSoarIntegrationsConfigure
- cloudSoarIncidentManageInvestigators
- cloudSoarIncidentAccess
- cloudSoarAuditAndInformationLicenseInformation
- cloudSoarIncidentBulkOperations
- cloudSoarCustomizationFields
- cloudSoarIncidentTaskEdit
- cloudSoarDashboardAccess
- cloudSoarIncidentAttachmentsEdit
- cloudSoarIncidentFoldersEdit
- cloudSoarUserManagementGroups
- cloudSoarIncidentPlaybooksAccess
- cloudSoarIncidentWarRoomUse
- cloudSoarReportAccess
- cloudSoarAuditAndInformationAuditTrail
- cloudSoarAutomationRulesAccess
- cloudSoarIncidentTriageChangeOwnership
- cloudSoarObservabilityManagement
- name: autofill_dependencies
value: {{ autofill_dependencies }}
description: |
Set this to true if you want to automatically append all missing capability requirements. If set to false an error will be thrown if any capabilities are missing their dependencies.
default: true
UPDATE examples​
- update
Update an existing role in the organization.
UPDATE sumologic.roles.roles_v2
SET
name = '{{ name }}',
description = '{{ description }}',
log_analytics_filter = '{{ log_analytics_filter }}',
audit_data_filter = '{{ audit_data_filter }}',
security_data_filter = '{{ security_data_filter }}',
selection_type = '{{ selection_type }}',
selected_views = '{{ selected_views }}',
users = '{{ users }}',
capabilities = '{{ capabilities }}',
autofill_dependencies = {{ autofill_dependencies }}
WHERE
id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND audit_data_filter = '{{ audit_data_filter }}' --required
AND capabilities = '{{ capabilities }}' --required
AND description = '{{ description }}' --required
AND log_analytics_filter = '{{ log_analytics_filter }}' --required
AND name = '{{ name }}' --required
AND security_data_filter = '{{ security_data_filter }}' --required
AND selected_views = '{{ selected_views }}' --required
AND selection_type = '{{ selection_type }}' --required
AND users = '{{ users }}' --required
RETURNING
id,
name,
audit_data_filter,
autofill_dependencies,
capabilities,
created_at,
created_by,
description,
log_analytics_filter,
modified_at,
modified_by,
security_data_filter,
selected_views,
selection_type,
system_defined,
users;
DELETE examples​
- delete
Delete a role with the given identifier from the organization.
DELETE FROM sumologic.roles.roles_v2
WHERE id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;
Lifecycle Methods​
EXEC variables use wire (API) names.
- assign_user
- remove_user
Assign a role to a user in the organization.
EXEC sumologic.roles.roles_v2.assign_user
@roleId='{{ roleId }}' --required,
@userId='{{ userId }}' --required,
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;
Remove a role from a user in the organization.
EXEC sumologic.roles.roles_v2.remove_user
@roleId='{{ roleId }}' --required,
@userId='{{ userId }}' --required,
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;