User Groups

User Groups allow you to group users and control what they have access to as a group. You can configure a user group’s permissions and assign a query to it. The permissions are applied to all the associated users.

../_images/LP_UA_UG_List.png

User Groups

There are two user groups by default.

  1. The LogPoint Administrator group has access to all the available features and settings in LogPoint system.

  2. The User Account Administrator group has all the permissions except the system-related permissions of the LogPoint Administrator user group.

You have to enable SOAR in LogPoint to configure SOAR-specific permissions for a particular user group. Once SOAR is enabled, the user group has access to all SOAR-specific permissions relevant to its permission group.

../_images/LP_Admin_SOAR.png

User Group Details

Note

  • You cannot edit or delete the default user groups.

  • The users in the User Account Administrator group cannot view the users in the LogPoint Administrator group.

Adding a User Group

  1. Go to Settings >> User Accounts from the navigation bar and click User Groups.

../_images/LP_UA_UG_List_Add.png

User Groups

  1. Click Add.

../_images/LP_UA_UG_Add.png

Adding a User Group

  1. Enter a Name and a Description.

  2. Enter a Universal Query. LogPoint appends the universal query to each search query entered by the users of the group.

    For example, if you enter col_type = syslog as a user group’s universal query and search the term login, the system searches for login in the result set of col_type = syslog. The search query is equivalent to col_type = syslog and login for the users in this group.

  3. Select a Permission Group.

  4. Click the Object Permission drop-down and select repos, devices, device groups, and IP addresses where users of the user group can search the logs.

    ../_images/LP_UA_UG_ObjPermission1.png

    Object Permission

    6.1. Select Full Permission to allow the user group to access all repos, device groups, devices, and IP addresses.

    If you select Full Permission, all the repos, the device groups, and the devices added to the user group later are automatically considered in the object permission. This rule applies to any newly added LogPoint in the system.

    6.2. Select All Repos to allow the user group to access all repos.

    6.3. Select All Device Groups to allow the user group to access all the device groups, the devices, and the IP addresses of the system.

    6.4. To select specific repos, device groups, devices, and IP addresses, click the > symbol.

    ../_images/LP_UA_UG_ObjPermission2.png

    Devices and Repos Selector

    SELECT REPO AND DEVICE lists how they are mapped. You can choose between All selected, None selected and Some selected from the accompanying checkbox.

    ../_images/LP_UA_UG_ObjPermission_Select.png

    Repo, Device Groups, Devices, and IP Selector

    Note

    When you select All Selected for a device group, any device added to the group will automatically get the same object permissions.

  5. Click Ok after making the necessary selections.

  6. Click Submit.

Refer to Adding User Groups to an Incident User Group, Adding a User, and Mapping LDAP Groups to LogPoint User Groups to learn how user groups are used in LogPoint.

Note

Click the ? icon in the top-right corner to get help on the inputs.

Editing a User Group

  1. Go to Settings >> User Accounts from the navigation bar and click User Groups.

  2. Click the user group you want to edit.

../_images/LP_UA_UG_List_Edit.png

Editing a User Group

  1. Update the information.

  2. Click Submit.

Deleting User Groups

Before deleting a user group, make sure it’s not in use.

  1. Go to Settings >> User Accounts from the navigation bar and click User Groups.

  2. Click the Delete icon from the Actions column.

    ../_images/LP_UA_UG_List_Delete.png

    Deleting a User Group

    1. To delete multiple user groups, select the user groups, click the More drop-down, and select Delete Selected.

    ../_images/LP_UA_UG_List_DeleteSelected.png

    Deleting Multiple User Groups

    1. To delete all the user groups, click the More drop-down and select Delete All.

    ../_images/LP_UA_UG_List_DeleteAll.png

    Deleting All User Groups

  3. Click Yes to confirm.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support