05 Dec 2024 02:58 PM
We created log bucket for secure data + Allow policy for special group - but probably because of default policy "Storage Logs Read" - anyboddy still can access those logs.
Cannot find any example in Docs.
Is there any easy solution ? Or do we need to DENY access from other groups ??
BR, Josef
Solved! Go to Solution.
05 Dec 2024 06:06 PM
PFA Dynatrace Resource that contains answer to the related storage policy:
BR,
Peter
05 Dec 2024 08:49 PM
This is my usual strategy among my clients, but I'm also open to new ideas:
06 Dec 2024 02:05 PM
Thanks @AntonioSousa for detailed description.
10 Dec 2024 07:44 AM
Thank you Antonio !
Trying to implement it in first case - in fact just the log part now
ALLOW storage:buckets:read WHERE storage:bucket-name = "special_bucket";
Plus removing the "Read Logs" and "Environment role - View logs" policies.
BR, Josef
22 Jan 2025 02:15 PM
Hi Antonio,
how you are defining access to PARTICULAR standard entities and metrics - hosts, processes, services, requests, traces, apps, user actions ? Via policy boundaries ?
Are you still using management zones ?
BR, Josef