Skip to content

Commit 4e5cc96

Browse files
authored
Add prisma_cloud data streams to kibana_system role permissions (#138218) (#138278)
Adding logs-prisma_cloud.misconfiguration-* and logs-prisma_cloud.vulnerability-* data stream indices to the kibana_system privileges. This is required for the latest transform to work. (cherry picked from commit 39d2bb8)
1 parent affb65f commit 4e5cc96

File tree

2 files changed

+4
-0
lines changed

2 files changed

+4
-0
lines changed

x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/store/KibanaOwnedReservedRoleDescriptors.java

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -491,6 +491,8 @@ static RoleDescriptor kibanaSystem(String name) {
491491
"logs-m365_defender.vulnerability-*",
492492
"logs-microsoft_defender_endpoint.vulnerability-*",
493493
"logs-microsoft_defender_cloud.assessment-*",
494+
"logs-prisma_cloud.misconfiguration-*",
495+
"logs-prisma_cloud.vulnerability-*",
494496
"logs-sentinel_one.application_risk-*"
495497
)
496498
.privileges(

x-pack/plugin/core/src/test/java/org/elasticsearch/xpack/core/security/authz/store/ReservedRolesStoreTests.java

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1701,6 +1701,8 @@ public void testKibanaSystemRole() {
17011701
"logs-m365_defender.vulnerability-" + randomAlphaOfLength(randomIntBetween(0, 13)),
17021702
"logs-microsoft_defender_endpoint.vulnerability-" + randomAlphaOfLength(randomIntBetween(0, 13)),
17031703
"logs-microsoft_defender_cloud.assessment-" + randomAlphaOfLength(randomIntBetween(0, 13)),
1704+
"logs-prisma_cloud.misconfiguration-" + randomAlphaOfLength(randomIntBetween(0, 13)),
1705+
"logs-prisma_cloud.vulnerability-" + randomAlphaOfLength(randomIntBetween(0, 13)),
17041706
"logs-sentinel_one.application_risk-" + randomAlphaOfLength(randomIntBetween(0, 13))
17051707
).forEach(indexName -> {
17061708
final IndexAbstraction indexAbstraction = mockIndexAbstraction(indexName);

0 commit comments

Comments
 (0)