Granting or Removing Resource Permissions

Caution: Be sure to set permissions on resources and permissions on events appropriately for user groups.

Preventing users from viewing groups of resources does not necessarily prevent those same users from viewing event data on those resources.

Users with permissions to view certain events (determined by event filters as described here), can view all event fields for those particular events (in reports, query viewers, and so forth) even if they do not have permissions on some resources reflected in the event data.

For example, a user with no read permissions on an asset could still have permissions to view event data related to the asset, and thereby have access to the data contained in the event fields (such as server name, IP address) in the context of that event.

As a best practice, keep the above in mind when granting permissions on events. Otherwise, you might give some users a view into resource information through event data that you did not intend for them to see.

Where: Navigator > Resources > Users > user group

To grant permissions to resources:

  1. Right-click a user group and select Edit Access Control.

  2. In the ACL Editor, select the Resources tab.

    Available resources are listed based on user permissions, therefore the list of resources will not be the same for each group.

  3. Add or remove permissions on a resource for this user group as follows.

  4. Click OK on the User Group ACL Editor to save changes to Resources permissions.