Kaspersky Next XDR Expert

Granular access to events

Expand all | Collapse all

In KUMA, users with different rights can have granular access to events. Access to events is controlled at the level of storage spaces.

You can assign spaces to users in the Spaces permissions section. After upgrading to the latest version, the 'All spaces' space set is assigned to all existing users, that is, access to all spaces is unrestricted. An event contains a tenant ID and a space ID, therefore the user needs rights to the corresponding tenant and space to have access to the event.

Keep in mind the following special considerations involved in displaying storages:

  • If a storage is not listed in the Active services section, the storage and its spaces are not displayed in the list of spaces of the set.
  • If the storage service was stopped using the systemctl stop kuma-<storage ID> command, the storage and its spaces are not displayed in the list of spaces of the set.
  • If the storage was started and then deleted using the uninstall command, the storage and its spaces remain in the list of spaces of the set.

In the list of events, you can add the SpaceID field to the table, which will display the name of the space. The space of audit events is displayed as KUMA Audit. KUMA Default is the space inside each storage, where all events go if the storage does not have configured spaces or if the event does not match the conditions of the existing spaces.

When you export the list of events to a TSV file, the space ID and name are displayed for spaces.

To differentiate access:

  1. Configure the space sets.

    You can create, edit, or delete space sets. These actions result in audit events.

  2. Configure the access rights of the space set: you can grant or revoke access rights of selected users.

Creating a space set

Editing a space set

Deleting a space set

Grant access to a space set

Revoke access to a space set

Use cases

Migrating to the latest KUMA version with differentiated access to events

Restricting access to spaces for all users

Allowing some users to view all events

Permitting some users to view events from a finite set of spaces

Supplementing an explicitly specified space set for a user

Editing a space set

Deleting a space set