As an administrator, you can use access groups to enable users with analyst and monitor roles to modify and delete YARA roles in the Network Security appliance. By default, these users have read-only privilege.
Users that you add to this access group can upload and delete YARA rules in addition to the privileges assigned to their role.
Follow the below steps to authorize the access group users to modify the YARA rules:
Enable the
yara_rulesarea for access groups. See Enabling and disabling access groups for YARA rules.Create an access group. See Creating access groups for YARA rules.
Authorize the group with the access group command option
match-yara-rules-access.Important
The
match-yara-rules-accesscommand option authorizes users of an access group to modify and delete YARA rules.Add the users required to the access group to let them modify and delete YARA rules. See Adding a user to the YARA rules access group.