<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is possible create a custom admin role with a specific filter? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35310#M38108</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This question is for administration of PANORAMA and PALOALTO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know, if is possible to create a custom admin role with a specific filter. For example, If I make a admin role for vsys or device group and check Monitor-Logs-Threats I want to that the users of this role only can view the logs of virus and wildfire, and the other threats the can not view.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible to custom at this level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Angel R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jun 2015 15:08:00 GMT</pubDate>
    <dc:creator>aromero</dc:creator>
    <dc:date>2015-06-16T15:08:00Z</dc:date>
    <item>
      <title>Is possible create a custom admin role with a specific filter?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35310#M38108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This question is for administration of PANORAMA and PALOALTO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know, if is possible to create a custom admin role with a specific filter. For example, If I make a admin role for vsys or device group and check Monitor-Logs-Threats I want to that the users of this role only can view the logs of virus and wildfire, and the other threats the can not view.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible to custom at this level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Angel R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jun 2015 15:08:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35310#M38108</guid>
      <dc:creator>aromero</dc:creator>
      <dc:date>2015-06-16T15:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is possible create a custom admin role with a specific filter?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35311#M38109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Panorama cannot distinguish vsys level users and as of PanOS 6.1 you do not have the option to restrict users by device group.&amp;nbsp; I've not used PanOS 7 to see if they are added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would be a feature request you could discuss with your sales engineer.&amp;nbsp; If there is an existing request you can vote for it if this is new he can create a feature request and give you the number.&amp;nbsp; Once you have the FR number post it on the forums to encourage others to vote too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jun 2015 10:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35311#M38109</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-20T10:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is possible create a custom admin role with a specific filter?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35312#M38110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;This is true. But in PANORAMA, if you first add an Access Domain where you select only a Device Group in mode read that is the same of the Vsys of PALO ALTO, and later you add an Admin Role where you only select Monitor - Log - Threats and Privacy -&amp;nbsp; Show Full IP Address. This 2 object can be used when you create an administrator user of type "Device Group adn Template Admin".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when this user open the GUI Console, only will see the Threat Log on the label Monitor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now , I am trying to customize this display for this special administrator user. For example, that only can be view application smtp, and other query is deny. Also, if is possible that the area filter it was blocked or gray. I like too to customize the columns, moving the order for all the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From CLI, to this users I have add a preference of a query:&lt;/P&gt;&lt;P&gt;set mgt-config users VIEWER1_SMTP preferences saved-log-query threat Wildfire_SMTP query "( subtype eq wildfire-virus ) and ( app eq smtp )"&lt;/P&gt;&lt;P&gt;This configuration i have add in multiple similar users VIEWER2, VIEWER3....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i dont know if is possible to make more customization using CLI with the command SET. Because preference dont give me more values or the admin role dont show me more options for customizations. I think that if I really need all this, I will to have a resquest of a feature as you say me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the information with the config outpout in mode set:&lt;/P&gt;&lt;P&gt;show mgt-config users VIEWER1_SMTP&lt;/P&gt;&lt;P&gt;set mgt-config users &lt;SPAN style="font-size: 13.3333330154419px;"&gt;VIEWER1_SMTP&lt;/SPAN&gt; permissions role-based custom dg-template-profiles RO_DG_INTERNET profile INTERNET&lt;/P&gt;&lt;P&gt;set mgt-config users &lt;SPAN style="font-size: 13.3333330154419px;"&gt;VIEWER1_SMTP&lt;/SPAN&gt; authentication-profile Auth-AD&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;set mgt-config users VIEWER1_SMTP preferences saved-log-query threat Wildfire_SMTP query "( subtype eq wildfire-virus ) and ( app eq smtp )"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;show shared admin-role INTERNET&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;set shared admin-role INTERNET role device-group webui monitor logs threat enable&lt;/P&gt;&lt;P&gt;set shared admin-role INTERNET role device-group webui privacy show-full-ip-addresses enable&lt;/P&gt;&lt;P&gt;set shared admin-role INTERNET role device-group webui privacy show-user-names-in-logs-and-reports enable&lt;/P&gt;&lt;P&gt;set shared admin-role INTERNET role device-group contextswitch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show mgt-config access-domain&lt;/P&gt;&lt;P&gt;set mgt-config access-domain &lt;SPAN style="font-size: 13.3333330154419px;"&gt;RO_DG_INTERNET&lt;/SPAN&gt; device-groups DG_INTERNET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show readonly dg-meta-data dginfo DG_INTERNET&lt;/P&gt;&lt;P&gt;set readonly dg-meta-data dginfo DG_INTERNET dg-id 11&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 14:07:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-possible-create-a-custom-admin-role-with-a-specific-filter/m-p/35312#M38110</guid>
      <dc:creator>aromero</dc:creator>
      <dc:date>2015-06-26T14:07:07Z</dc:date>
    </item>
  </channel>
</rss>

