we would like to give our analysts the option to create detection rules, but they should not be able to activate them. The engineer should only be able to activate them after an engineer has looked at them.
However, we have not found a way to restrict a user's rights to detection rules. If you do this via the index permissions, the user is also extremely restricted when it comes to case and alarm processing.
Have we overlooked something here or is it really not possible? If it doesn't work, we would really like this feature.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.