Skip to main content

HelloID

Grant access to audit logs

By default, no one has access to Audit logs—not even HelloID administrators. To start viewing reports, do the following:

  1. If you do not already have the following Groups in your HelloID environment, add them. See Add a local group.

    • Elastic_Reports_Read

    • Elastic_Reports_Write

    2022-10-18_11-01-14.jpg
  2. If you do not already have the following Roles in your HelloID environment, add them. See Add a role.

    • ElasticRead

    • ElasticWrite

    2022-10-18_11-07-00.jpg
    1. Configure these roles with the following Rights, respectively. See Configure rights for a role.

    2. Assign these roles the Elastic_Reports_Read and Elastic_Reports_Write groups, respectively. See Link a role to a group.

      2022-11-28_14-07-03.jpg
      2022-11-28_14-07-25.jpg
  3. For the Elastic_Reports_Read group, Grant a group access to a report space for each of the four Built-in report spaces. Grant Read Only access for each report space.

    2022-10-18_11-22-59.jpg
    2022-10-18_11-23-29.jpg
    2022-10-18_11-23-48.jpg
    2022-10-18_11-24-04.jpg
  4. Finally, assign your administrator account to the Elastic_Reports_Read and Elastic_Reports_Write groups. To do so, Link a group to a user.

    Important

    Access to audit logs requires groups to have both the relevant rights and access to the relevant report spaces.

    2022-10-17_13-47-03.jpg
    2022-10-17_13-47-27.jpg
  5. Log out and back in to HelloID. You will now have access to all Audit log reports.

  6. Optional: To grant additional users and/or groups access to audit logs, Link a group to a user and/or Link a group to a group for the Elastic_Reports_Read and Elastic_Reports_Write groups. They will have access to audit log reports after logging out and back in to HelloID.

    Tip

    To control access on a more granular basis (i.e., access only to certain report spaces), Add a local group and then assign that group to the Elastic_Reports_Read group (see Link a group to a group). Then, assign that group only to the relevant report spaces (see Grant a group access to a report space). Finally, assign users to the group as needed (see Link a group to a user).

    Note

    The Elastic_Reports_Write group is only used for Custom report spaces.