Adding or Removing Enforced Filters

About:

Enforced filters define which events a user group can view. By default, all new groups cannot view any events. If you view the Events tab on a new group's ACL Editor, the filter is shown as

/All Filters/Arcsight System/Core/No Events

After you add filters to this tab, these filters become the user group's enforced filters that are enforced at run time. The filters you add can be ArcSight-provided filters or filters you created, based on individual groups’ requirements.

By default, members of the administrators group can view all events, as indicated by the Administrators group's enforced filter: /All Filters/ArcSight System/Core/All Events.

Prerequisite:

Event filters must be available before you can add them to the Events tab of the ACL Editor for the user group. For more information about filters in general, see Filtering Events. For more information about events, see Events and Event Categorization.

Important notes about enforced filters:

Where: Navigator > Resources > Users > user group

  1. Right-click the user group and select Edit Access Control.

  2. In the ACL Editor, select the Events tab.

    The default enforced filter is listed on the tab.

    Caution: Be sure to set permissions on resources and permissions on events appropriately for user groups.

    Preventing users from viewing groups of resources does not necessarily prevent those same users from viewing event data on those resources.

    Users with permissions to view certain events (determined by event filters as described here), can view all event fields for those particular events (in reports, query viewers, and so forth) even if they do not have permissions on some resources reflected in the event data.

    For example, a user with no read permissions on an asset could still have permissions to view event data related to the asset, and thereby have access to the data contained in the event fields (such as server name, IP address) in the context of that event.

    As a best practice, keep the above in mind when granting permissions on events. Otherwise, you might give some users a view into resource information through event data that you did not intend for them to see.

  3. Add or remove user group permissions to view events as follows.

  4. Click OK on the User Group ACL Editor to save changes to Operations permissions.