ExtraHop 8.8 ExtraHop Trace Admin UI Guide
37
Here is a list of available permission attributes, values, and descriptions:
•
setup = 1
, which allows the user to create and modify all objects and settings on the ExtraHop
system, including Administration settings
•
readwrite = 1
, which allows the user to create and modify all objects and settings on the
ExtraHop system, not including Administration settings
•
limited = 1
, which allows the user to create, modify, and share dashboards
•
readonly = 1
, which allows the user to view objects in the ExtraHop system
•
personal = 1
, which allows the user to create dashboards for themselves and modify any
dashboards that have been shared with them
•
limited_metrics = 1
, which allows the user to view shared dashboards
6. (Optional) Add the following attribute to allow users to view, acknowledge, and hide detections that
appear in the ExtraHop system.
•
detectionsaccessfull = 1
7. (Optional) If you have a Trace appliance, add an attribute to allow users to download packet captures
or packet captures with associated session keys.
Here is a list of the available packet capture attributes and values:
•
packetsfull = 1
, which allows users with any privilege level to view and download packets
•
packetsfullwithkeys = 1
, which allows users with any privilege level to view and download
packets and associated session keys stored on the Trace appliance
API Access
The API Access page enables you to generate, view, and manage access for the API keys that are required
to perform operations through the ExtraHop REST API.
Manage API key access
Users with unlimited privileges can configure whether users can generate API keys for the ExtraHop
system. You can allow only local users to generate keys, or you can also disable API key generation entirely.
Users must generate an API key before they can perform operations through the ExtraHop REST API. Keys
can be viewed only by the user who generated the key or system administrators with unlimited privileges.
After a user generates an API key, they must append the key to their request headers.
1. Log in to the Administration settings on the ExtraHop system through
https://<extrahop-
hostname-or-IP-address>/admin
.
2. In the Access Settings section, click
API Access
.
3. In the Manage API Access section, select one of the following options:
•
Allow all users to generate an API key
: Local and remote users can generate API keys.
•
Only local users can generate an API key
: Remote users cannot generate API keys.
•
No users can generate an API key
: No API keys can be generated by any user.
4. Click
Save Settings
.
Configure cross-origin resource sharing (CORS)
Cross-origin resource sharing (CORS) allows you to access the ExtraHop REST API across domain-
boundaries and from specified web pages without requiring the request to travel through a proxy server.
You can configure one or more allowed origins or you can allow access to the ExtraHop REST API from any
origin. Only administrative users with unlimited privileges can view and edit CORS settings.
1. In the
Access Settings
section, click
API Access
.
2. In the CORS Settings section, specify one of the following access configurations.
Содержание Trace Admin UI
Страница 1: ...ExtraHop 8 8 ExtraHop Trace Admin UI Guide...