You can use access groups to control which alerts users with the analyst and monitor roles can view and manage. The system processes two types of rules to authorize access to alerts.
Access group rules define the criteria that must be matched in an alert that the Central Management System appliance receives from a managed Network Security or Email Security — Server appliance or from a managed Email Security - Cloud instance. If an alert matches the criteria defined by the access group rules applied to an access group, users in that access group can view and manage that alert. You can define multiple access group rules for an access group.
Authorization rules define the criteria that must be matched in the Central Management System Web UI login request. If there is a match, the user is added to the access group associated with the rule. You can define multiple authorization rules for an access group.
For example, suppose a Central Management System appliance manages Network Security and Email Security — Server appliances. An authorization rule specifies that members of the infosec LDAP group are added to the nx-alerts access group. The access group rules defined for the nx-alerts access group specify that all alerts from managed Network Security appliances should be displayed, except for alerts with "minor" severity. When Joe (a member of the infosec LDAP group) logs in to the Central Management System Web UI, he will see the Alerts > NX pages, but not the Alerts > EX pages. The Alerts > NX pages will show all major and critical alerts from all managed Network Security appliances.
Note
This feature only affects users with the analyst and monitor roles.
Users with the admin role have unlimited access to alerts, and users with other roles have no access to alerts by default; however, the admin can configure full UI access to non-administrators with the aaa authorization access-groups group <group name> rules rule command. Access groups have no effect on what users can do with alerts. Analyst and monitor users can both view and manage the alerts to which they have access.
Analyst and monitor users have no access to the CM Dashboard or the Reports pages when this feature is enabled.
Task list for configuring access groups for alerts
Perform the tasks in the specified order to configure access groups for alerts.
Create access groups. See Creating access groups for alerts.
Define access group rules. See Defining access group rules.
Define authorization rules. See Defining authorization rules.
Enable access groups. See Enabling access groups for alerts.