Skip to main content

Responses are generated using AI and may contain mistakes.

Log StreamLog Stream Guide

Access Log Stream

Log Stream is available from a tile on the New-Scale Security Operations Platform home page.

Accessing the Log Stream Home Page

  1. Log on to the New-Scale Security Operations Platform.

  2. Select the Log Stream tile.

    The Log Stream home page appears. There are several tabs on the home page:

Controlling Log Stream Permissions

User access to Log Stream is managed through Universal Role-Based Access (URBA) on the Exabeam Security Operations Platform. URBA includes two permission levels for Log Stream users:

  • Read Access – Read only permissions. This level of access allows users to view parsers, parser updates, enrichment rules, and event filters. It does not provide access to make any modifications.

    Note

    Any options in the Log Stream UI that allow creating, editing, or deleting anything are not available to users with this level of access.

  • Manage Access – Read, write, and delete permissions. This level of access allows users to create and edit parsers, parser updates, enrichment rules, and event filters. The full set of all Log Stream options is available to users with this level of access.

You can assign Log Stream access levels to default user roles that exist in your Exabeam Settings, or you can create custom roles and define specific permissions. The table below shows the Log Stream permissions that are available to assign and it also shows which default roles already include those permissions. Permission settings for Log Stream look like the following:

rbac-permissions.png

For more information about managing user permissions and creating custom roles, see User Roles and Local Users in the Security Operations Platform Guide.

Permission

Description

Access

Default Roles

Log Stream

View or ManageParsers, Parser Updates, Enrichment, and Event Filtering and Routing

Read, Write, Delete

  • Administrator

  • Security Engineer

Read

Tier 3 Analyst

Note

Tier 1 and Tier 2 Analyst user roles do not have any access to Log Stream by default. Those users will not see the Log Stream tile in the New-Scale Security Operations Platform.