Skip to main content

Exabeam Security Operations PlatformExabeam Security Operations Platform Administration Guide

User Permissions

Each default and custom role defines the specific permissions entitled to users with that role assignment. Permissions are grouped by permission categories as described in the following topics:

APIs Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Application Programming Interfaces

New-Scale

Manage API keys

View and manage API keys.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Developer

Application Programming Interfaces

New-Scale

Manage webhooks

View and manage webhooks.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Developer

Collectors Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Cloud Collectors

New-Scale

Cloud Collectors

View and manage Cloud Collectors.

Read

  • Administrator

  • Security Engineer

  • Administrator (SaaS Cloud Connectors)

Cloud Collectors

New-Scale

Cloud Collectors

View and manage Cloud Collectors.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Administrator (SaaS Cloud Connectors)

SaaS Cloud Connectors

SaaS

SaaS Cloud Connectors

View and manage SaaS Cloud Connectors

Read

  • Administrator

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Administrator (Data Lake)

  • Administrator (SaaS Cloud Connectors)

SaaS Cloud Connectors

SaaS

SaaS Cloud Connectors

View and manage SaaS Cloud Connectors

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Administrator (Data Lake)

  • Administrator (SaaS Cloud Connectors)

SaaS Site Collectors

SaaS

SaaS Site Collectors manage collectors

Perform all collector operations, such as managing collectors, changing template assignments, and toggling operations in SaaS Site Collectors.

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Site Collectors

New-Scale

Site Collectors

View and manage Site Collectors' settings.

Read

  • Administrator

  • Security Engineer

Site Collectors

New-Scale

Site Collectors

View and manage Site Collectors' settings.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Site Management

New-Scale

Site Management

View and manage sites.

Read

  • Administrator

  • Security Engineer

Site Management

New-Scale

Site Management

View and manage sites

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Compliance Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Webhooks

New-Scale

Audit Events Export

Export audit events.

  • Read

  • Write

  • Administrator

  • Security Engineer

  • Compliance Manager

  • Administrator (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • Administrator (Data Lake)

  • Data Privacy Officer (Data Lake)

  • Administrator (SaaS Cloud Connectors)

Identity and Access Management Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Settings

New-Scale

User, roles, and single sign-on

View and manage users, roles, and single sign-on settings

Read

  • Administrator

  • Security Engineer

Settings

New-Scale

Identity and Access Management

View and manage users and associated roles

Read

  • Administrator

  • Security Engineer

Settings

New-Scale

Identity and Access Management

View and manage users and associated roles

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Settings

New-Scale

single sign-on configuration

View and manage single sign-on configurations.

Read

  • Administrator

  • Security Engineer

Settings

New-Scale

single sign-on configuration

View and manage single sign-on configurations.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Investigation and Response Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Advanced Analytics

SaaS

Advanced Analytics add comments

Add comments for entities in Advanced Analytics.

  • Read

  • Write

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view unmasked data (PII)

View personally identifiable information (PII) when data masking is enabled in Advanced Analytics.

Read

Data Privacy Officer (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics approve lockouts

Accept account lockout activities for users in Advanced Analytics. Accepting lockouts indicates that the specific set of behaviors are deemed normal and allowed for that user.

  • Read

  • Write

Tier 3 Analyst (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics send incidents to Incident Responder

Send incidents to Incident Responder from Advanced Analytics.

  • Read

  • Write

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Alert Triage

New-Scale

Alert Rank

View and manage Alert Rank.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

Alert Triage

New-Scale

Alert Triage

View and manage Alert Triage

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

Alert Triage

New-Scale

Alert Triage Public Saved Filters

View and manage public saved filters.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 1 Analyst

Automation Management

New-Scale

Automation Management playbooks

View and manage playbooks in Automation Management.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Automation Management

New-Scale

Automation Management playbooks

View and manage playbooks in Automation Management.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Case Manager

SaaS

Case Manager read, write, and delete incidents

Edit incidents in Case Manager

  • Read

  • Write

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager bulk edit

Edit multiple incidents at the same time in Case Manager.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager read, write, and delete incidents

View incidents in Case Manager.

Read

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Case Manager

SaaS

Case Manager add comments

Add comments in Case Manager.

  • Read

  • Write

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager create incidents

Create incidents in Case Manager.

  • Read

  • Write

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager read, write, and delete incidents

Delete incidents in Case Manager

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager view comments

View case comments in Case Manager.

Read

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Case Manager

SaaS

Case Manager view restricted incidents

View incidents restricted to other users or groups in Case Manager.

Read

  • Administrator (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Dashboards

New-Scale

Dashboards Case Management

View and manage Case Management Dashboards.

Read

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Dashboards

New-Scale

Dashboards Case Management

View and manage Case Management Dashboards.

  • Read

  • Write

  • Delete

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Incident Responder

SaaS

Incident Responder run playbooks

Run playbooks from the workbench in Incident Responder.

  • Read

  • Write

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder run actions

Launch individual actions from the user interface in Incident Responder.

  • Read

  • Write

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

Threat Center

New-Scale

Threat Center alerts

View and manage alerts in Threat Center.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Threat Center

New-Scale

Threat Center alerts

View and manage alerts in Threat Center.

  • Read

  • Write

  • Delete

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Threat Center

New-Scale

Threat Center cases

View and manage cases in Threat Center.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Threat Center

New-Scale

Threat Center cases

View and manage cases in Threat Center.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Threat Center

New-Scale

Threat Center detection grouping rules

View and manage detection grouping rules in Threat Center.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Threat Center

New-Scale

Threat Center detection grouping rules

Manage detection grouping rules in Threat Center.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Platform Insights Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Advanced Analytics

SaaS

Advanced Analytics view health

Advanced Analytics view system health.

Read

Administrator (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view trends

View overall trends with Advanced Analytics.

Read

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Notifications

New-Scale

Configure global notification channels

View and manage global notification channels for your organization.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Notifications

New-Scale

Manage security notifications

View and manage security notifications for your profile.

  • Read

  • Write

  • Delete

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Compliance Manager

Notifications

New-Scale

Manage health notifications

View and manage health notifications for your profile.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Notifications

New-Scale

Manage consumption notifications

View and manage consumption notifications for your profile.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Notifications

New-Scale

Manage thirdparty-access

View and manage third-party access notifications for your profile.

  • Read

  • Write

  • Delete

Administrator

Outcomes Navigator

New-Scale

Outcomes Navigator

View Outcomes Navigator.

Read

  • Administrator

  • Security Engineer

Security Management Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Action Editor

New-Scale

Actions Editor

View and manage custom actions.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

Advanced Analytics

SaaS

Advanced Analytics manage content packages

View and manage content packages for automatic installation in Advanced Analytics.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Administrator (Data Lake)

Advanced Analytics

SaaS

Advanced Analytics administrative operations

Perform all administrative operations in Advanced Analytics.

  • Read

  • Write

  • Delete

Administrator (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics manage watchlists

Add and remove users from the watchlists in Advanced Analytics.

  • Read

  • Write

  • Delete

  • Tier 3 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view rules

View rules that determine how security events are handled in Advanced Analytics.

Read

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics manage data ingestion

Configure log sources, feeds, and email ingestion in Advanced Analytics.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Advanced Analytics

SaaS

Event Selection streams

View or modify streams in Advanced Analytics with Event Selection.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Advanced Analytics

SaaS

Event Selection streams

View or modify streams in Advanced Analytics with Event Selection.

Read

Administrator

Auto Parser Generator

New-Scale

Manage Auto Parser Generator

View and manage SaaS parsers in Auto Parser Generator.

Read

  • Administrator

  • Security Engineer

Case Manager

SaaS

Case Manager manage queues

View and manage membership to queues in Case Manager.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager manage incident rules

View and manage rules for how incidents are assigned, restricted, and prioritized on ingestion in Case Manager.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager manage rules

View and manage rules that determine how security events are handled in Case Manager.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager manage incident configuration

View and manage incident configurations including incident types, fields, layouts, case notifications, and checklists in Case Manager.

  • Read

  • Write

  • Delete

Administrator (Advanced Analytics)

Case Manager

SaaS

Case Manager manage bi-directional Communication

Configure inbound and outbound settings for bidirectional communications in Case Manager.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Case Manager

SaaS

Case Manager delete entities and artifacts

Delete entities and artifacts in Case Manager.

  • Read

  • Write

  • Delete

Case Manager

SaaS

Case Manager manage checklist definitions

Configure checklist definitions in Case Manager.

  • Read

  • Write

  • Delete

Case Manager

SaaS

Case Manager manage incident definitions

View and manage incident definitions in Case Manager.

  • Read

  • Write

  • Delete

Context Management

New-Scale

Context Management

View and manage Context Management configuration.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Context Management

New-Scale

Context Management

View and manage Context Management configuration.

Read

  • Administrator

  • Security Engineer

Correlation Rules

New-Scale

Correlation Rules

View and manage correlation rules.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

  • Tier 1 Analyst (Data Lake)

  • Auditor (Data Lake)

  • Data Privacy Officer (Data Lake)

  • CloudOpsMonitoring (Data Lake)

  • Administrator (SaaS Cloud Connectors)

Correlation Rules

New-Scale

Correlation Rules

View and manage correlation rules.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

Data Lake

SaaS

Data Lake manage indices

Re-parse and re-index the logs of indices in Data Lake

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Data Lake

SaaS

Data Lake manage correlation rules

View and manage correlation rules in Data Lake.

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Data Lake

SaaS

Data Lake manage data access

View and manage data access rules in Data Lake

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Data Lake

SaaS

Data Lake view saved objects

View saved searches, visualizations, dashboards, and reports in Data Lake.

Read

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

  • Tier 1 Analyst (Data Lake)

  • Auditor (Data Lake)

  • Data Privacy Officer (Data Lake)

  • CloudOpsMonitoring (Data Lake)

Data Lake

SaaS

Data Lake manage saved objects

View and manage saved searches, visualizations, dashboards, and reports in Data Lake.

  • Read

  • Write

  • Delete

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

  • Tier 1 Analyst (Data Lake)

  • Auditor (Data Lake)

  • Data Privacy Officer (Data Lake)

  • CloudOpsMonitoring (Data Lake)

Data Lake

SaaS

Data Lake manage Kafka Connect

View and manage connectors in Kafka Connect in Data Lake.

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Data Lake

SaaS

Data Lake manage cross-cluster connection

Add and edit the connection to remote clusters in Data Lake.

  • Read

  • Write

  • Delete

Administrator (Data Lake)

Entity Management

New-Scale

Attack Surface Insights

View and manage Attack Surface Insights.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Administrator (SaaS Cloud Connectors)

Entity Management

New-Scale

Attack Surface Insights

View and manage Attack Surface Insights.

  • Read

  • Write

  • Delete

Administrator

Incident Responder

SaaS

Incident Responder reset incident workbench

Reset incident workbench

  • Read

  • Write

  • Security Engineer

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder manage playbooks

Manage playbooks in Incident Responder.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder manage services

View and manage services (third-party integrations) in Incident Responder.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder manage playbook templates.

View and manage playbook templates

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder manage triggers

View and manage playbook triggers in Incident Responder.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Incident Responder

SaaS

Incident Responder manage custom services and packages

Manage custom services and related packages in Incident Responder.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Log Stream

New-Scale

Manage Log Stream Parsers

View and manage parsers, parser updates, view live parsed events, and re-parsing jobs in Log Stream.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

SaaS Context Collectors

SaaS

SaaS context tables manage users and context sources

View and manage users, roles, and context sources for decision support in SaaS.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Administrator (Data Lake)

SaaS context tables

SaaS

SaaS manage context tables

View and manage entities and other objects in SaaS context tables.

  • Read

  • Write

  • Delete

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

Search

New-Scale

Secured Resources

View and manage Secured Resources.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Search

New-Scale

Secured Resources

View and manage Secured Resources.

Read

  • Administrator

  • Security Engineer

Search

New-Scale

Manage data retention settings

View and manage data retention.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Settings

New-Scale

Manage Administrative Settings

View and manage administrative settings.

Read

  • Administrator

  • Security Engineer

  • Developer

Settings

New-Scale

Manage Administrative Settings

View and manage administrative settings.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Developer

Threat Detection Management

New-Scale

Analytics Rules

View or manage Analytics Rules.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

Threat Detection Management

New-Scale

Analytics Rules

View or manage Analytics Rules.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Threat Detection Management

New-Scale

Universal Prioritization

View or manage Universal Prioritization.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

Threat Detection Management

New-Scale

Universal Prioritization

View or manage Universal Prioritization.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

Threat Detection Permissions

Application

Platform

Permission

Permission Description

Access

Roles

Advanced Analytics

SaaS

Advanced Analytics threat hunter search incidents

Perform basic threat hunter incident searches in Advanced Analytics. Basic threat hunter incident search allows one to search for an incident and associated details.

Read

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics manage threat hunter search library

View and manage threat hunter saved searches in Advanced Analytics.

  • Read

  • Write

  • Delete

  • Tier 3 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view executive info

View the risk reasons and timeline of the executive users in the organization. You will be able to see the activities performed by executive users along with the associated anomalies.

Read

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view global insights

View the organizational models and histograms showing normal behavior for users and assets in Advanced Analytics.

Read

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics threat hunting

Perform threat hunting in Advanced Analytics.

Read

  • Tier 3 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view data insights

View the normal behaviors for specific users and assets in Advanced Analytics.

Read

  • Tier 2 Analyst

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view threat hunter search library

View the Threat Hunter Search Library and the corresponding search results in Advanced Analytics.

Read

  • Tier 2 Analyst

  • Tier 3 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics manage threat hunter public searches

View and manage saved threat hunter public searches.

  • Read

  • Write

  • Delete

Tier 3 Analyst (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view notable activities

View all notable users, assets, sessions, and related risk reasons in Advanced Analytics.

Read

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics view raw logs

View the raw logs that are used to build the events in the Advanced Analytics timeline.

Read

  • Tier 2 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics threat hunter search

Perform basic threat hunter searches in Advanced Analytics. Basic threat hunter incident search allows one to search for a specific user, asset, session, or a security alert.

Read

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Advanced Analytics

SaaS

Advanced Analytics accept sessions

Allow a user to accept an Advanced Analytics session.

  • Read

  • Write

  • Tier 3 Analyst (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

Dashboards

New-Scale

Dashboards

View and manage dashboards.

Read

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Compliance Manager

Dashboards

New-Scale

Dashboards

View and manage dashboards.

  • Read

  • Write

  • Delete

  • Administrator

  • Security Engineer

  • Tier 3 Analyst

  • Tier 2 Analyst

Dashboards

New-Scale

Dashboards Anomalies

View and manage Anomalies Dashboards.

Read

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Tier 1 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Tier 1 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Dashboards

New-Scale

Dashboards Anomalies

View and manage Anomalies Dashboards.

  • Read

  • Write

  • Delete

  • Administrator

  • Tier 3 Analyst

  • Administrator (Advanced Analytics)

  • Tier 3 Analyst (Advanced Analytics)

  • Auditor (Advanced Analytics)

  • Data Privacy Officer (Advanced Analytics)

  • CloudOpsMonitoring (Advanced Analytics)

Dashboards

New-Scale

Dashboards Data Lake

View and manage Data Lake Dashboards.

Read

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

  • Tier 1 Analyst (Data Lake)

  • Auditor (Data Lake)

  • Data Privacy Officer (Data Lake)

  • CloudOpsMonitoring (Data Lake)

Dashboards

New-Scale

Dashboards Data Lake

View and manage Data Lake Dashboards.

  • Read

  • Write

  • Delete

  • Administrator

  • Tier 3 Analyst

  • Administrator (Data Lake)

  • Tier 3 Analyst (Data Lake)

  • Auditor (Data Lake)

  • Data Privacy Officer (Data Lake)

  • CloudOpsMonitoring (Data Lake)

Data Lake

SaaS

Data Lake run Elasticsearch Searches

Perform Elasticsearch search requests in Data Lake.

Read

Administrator (Data Lake)

Search

New-Scale

Search, Analyze and Export

Search, analyze, and export logs, alerts, and events.

Read

  • Administrator

  • Tier 3 Analyst

  • Tier 2 Analyst

  • Compliance Manager