Which data can a root domain access?
Overview
Currently, data access across domains affects only query data. Users in a root domain will be able to see events from data tables in all their child domains.
When a user in a root domain accesses the Data search area, they will see not only their own tables in the finder but all the tables with data in all their child domains.
Note that the table demo.ecommerce.data
won’t show any data in root domains. It won't appear in your finder and you will get an error if you try to query it using a free text query.
If a user in the root domain accesses a data table that contains events from different domains, they will see the owner of each specific event in the client column. This column will be added to all the tables in a root domain and is always located next to the eventdate column.
The users in the root domain will see the client column in all the queries, no matter the method used (Data search, Query API, Activeboards, Flow, OData feeds…)
It is important to mention that all the roles in the root domain will have access to the same data according to the rules set. If you need to limit access for specific roles in the domain, you can use custom finders and custom tables.
Also, note that a root domain will always have access to the following information by default:
All the Devo activity of the child domains in the
siem.logtrust.web.activity
table. Find more info about this table in this article.All the ingestion metrics of the child domains in the
siem.logtrust.collector.counter
table.All the alerts triggered in the child domains in the
siem.logtrust.alert.info
table. Find more info about this table in this article.Access to all the data in the child domains using the global search.
Note that root domains will not see any data from their child domains in the widgets of the Devo Home area.
Custom tables in root domains
my.app
and my.upload
tables defined in child domains will be also automatically available in the parent domain.
Besides, admin users in a root domain can define new my.app and my.upload tables directly from the finder. To do it: