This guide outlines the process to create a service account in Sumo Logic with read-only access to all components, including Cloud SIEM, SOAR, Alerts, Dashboards, Search, Insights, Indexes, Metrics, Collections, and Monitors.◼︎
Step 1: Log in with Admin Access
Log in to your Sumo Logic instance using an account with administrative privileges.
Step 2: Create a Role with Full Read-Only Permissions
Navigation: Administration → Security → Roles → Add Role
-
Role Name: AiStrikeReadOnlyRole
-
Description: Provides read-only access to all Sumo Logic components.
Enable the following permissions:
|
Category |
View Permissions |
|---|---|
|
Index Access |
(Controlled separately: Allow all/few indexes) |
|
Data Management |
View Collectors; View Fields; View Connections; View Scheduled Views; View Partitions; View Account Overview; Download Search Results; View * [All] |
|
Cloud SOAR |
View Cloud SOAR |
|
Cloud SIEM |
View Cloud SIEM; View Rules; View Threat Intelligence; View Match List; View File Analysis; View Customer Insights; View Network Blocks; View Mappings; View Entity; View * [All] |
|
Automation Service |
Task View |
|
Content |
View Rules; View Threat Intelligence; View Match Lists; View File Analysis; View Custom Insights; View Network Blocks; View Suppressed Entities; View * [All] |
|
Configuration [Optional] |
View Mappings; View Workflow; View Context Actions; View Actions; View Enrichments; View Custom Entity Types; View Entity; View Entity Normalization; View Entity Criticality; View Tag Schemas; View Entity Groups; View * [All] |
|
Alerting |
View Monitors; View Alerts; View Muting Schedules; View * [All] |
|
Threat Intel [Optional] |
View Threat Intel Data Store; View * [All] |
|
Organizations |
View Organisations |
Step 3: Assign Index Access
Navigation: Administration → Security → Roles → [AiStrikeReadOnlyRole] → Index Access
-
Select All Indexes or manually select required ones.
-
Click Save.
Step 4: Create a Service Account
Navigation: Administration → Security → Service Accounts → Add Service Account
-
Name: AiStrike_ReadOnly_Service_Account
-
Description: Service account with full read-only access for connectors and APIs.
-
Assign Role: AiStrikeReadOnlyRole
-
Add New Access Key/Secret Generation, keep scope for access key default
Once the account is created, copy and securely store the:
-
Access Key
-
Access Secret
These credentials are used to authenticate API requests and application integrations.
Step 5: Use the Service Account in Integrations
-
Access Key: <your_access_key>
-
Access Secret: <your_access_secret>
Share the access key and secret key with the AiStrike team.
If you face any issue, please reach out to the AiStrike technical team.