<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access permissions in cisco firewall app in Security</title>
    <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21634#M730</link>
    <description>&lt;P&gt;In Manager??Access controls &amp;gt;&amp;gt; Users...does your user (listed there) have 2 roles in the near right column...e.g. 1 you created / crafted specially AND a default one?&lt;BR /&gt;
If so, click on them and remove the default grey selected role....&lt;/P&gt;</description>
    <pubDate>Fri, 02 Nov 2012 15:39:39 GMT</pubDate>
    <dc:creator>DaveSavage</dc:creator>
    <dc:date>2012-11-02T15:39:39Z</dc:date>
    <item>
      <title>Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21629#M725</link>
      <description>&lt;P&gt;Hey Splunkers,&lt;/P&gt;

&lt;P&gt;I got a question hopefully someone can answer. In my setup I have the cisco security suite and cisco firewalls app installed, as well as the windows app. I am having problems with cisco firewall data showing up in a users overview. The user only has permissions to it's site's index that contains that sites domain controller. The user has inherited roles from the default user but in that role I have deleted having access to main and internal indexes. So the default user has access to no indexes. Then when I created the sites user I gave him access to only the one index. So why is firewall info from other indexes showing up in his firewall app overview?  &lt;/P&gt;

&lt;P&gt;Any help is appreciated, Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 14:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21629#M725</guid>
      <dc:creator>jaygirlardo</dc:creator>
      <dc:date>2012-11-02T14:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21630#M726</link>
      <description>&lt;P&gt;Jaygirlardo,&lt;BR /&gt;
These plug-ins use the index=firewall...and I guess that is the one you gave them access to?&lt;BR /&gt;
If a user ran a standard search...and hypothetically a firewall pushed its logs to, say, a syslog server...which has a forwarder on it...then the results &lt;EM&gt;may&lt;/EM&gt; go elsewhere e.g. 'main' which is the default?&lt;BR /&gt;
How, or at what level did you think you implemented the permission(s)?&lt;BR /&gt;
User level within Splunk are fairly generic (from Manager tab...but you prob already know that).&lt;BR /&gt;
Have you implemented any specific transforms?&lt;BR /&gt;
Br&lt;BR /&gt;
Dave&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21630#M726</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-02T15:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21631#M727</link>
      <description>&lt;P&gt;Indexes searched by default has to be 'clear all'd...I take  it you did that?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21631#M727</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-02T15:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21632#M728</link>
      <description>&lt;P&gt;Yes the firewall logs are going to a different index that they do not have permission to. I configred it right for the windows app because they only see windows info from their index, not any others. But somehow firewall info is viewable from their login.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21632#M728</guid>
      <dc:creator>jaygirlardo</dc:creator>
      <dc:date>2012-11-02T15:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21633#M729</link>
      <description>&lt;P&gt;Yes the firewall logs are going to a different index that they do not have permission to. I configred it right for the windows app because they only see windows info from their index, not any other window machines. But somehow firewall info is viewable from their login. for some reason I dont think it has to do with permissions. Maybe something the cisco firewall app does by default? I think I have a good idea how the roles and users work, but I could be wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21633#M729</guid>
      <dc:creator>jaygirlardo</dc:creator>
      <dc:date>2012-11-02T15:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21634#M730</link>
      <description>&lt;P&gt;In Manager??Access controls &amp;gt;&amp;gt; Users...does your user (listed there) have 2 roles in the near right column...e.g. 1 you created / crafted specially AND a default one?&lt;BR /&gt;
If so, click on them and remove the default grey selected role....&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21634#M730</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-02T15:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21635#M731</link>
      <description>&lt;P&gt;...and if it's not that (an over-sight I've made in the past ;-)...then you may need the orig author's 2-penneth.&lt;BR /&gt;
I did clock in the release notes that (for say ASAs which we use) the update as at Sept 10th indicates 'is now index independent')....hmm.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21635#M731</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-02T15:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access permissions in cisco firewall app</title>
      <link>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21636#M732</link>
      <description>&lt;P&gt;Yup, they only have the one role I assigned them. About index independent, what is?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 16:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Access-permissions-in-cisco-firewall-app/m-p/21636#M732</guid>
      <dc:creator>jaygirlardo</dc:creator>
      <dc:date>2012-11-02T16:03:55Z</dc:date>
    </item>
  </channel>
</rss>

