[SIEM][Detection Engine] Setup possible with read-only space privilege #56897
Labels
Feature:Detection Rules
Security Solution rules and Detection Engine
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Team:SIEM
Scenario:
Trying to set up the DE with reduced privileges.
Privileges:
manage_ilm
,manage_index_templates
all
on*
Read
on SIEMWhat did I do? Navigate to Detections tab
Behavior: Sets up the DE signals index even though the user has read-only space privileges.
Suggestion:
Do not try to set up signals index with only a
Read
space privilege.The text was updated successfully, but these errors were encountered: