Previous Topic: Step 7: Log in as a PCI-Analyst and Evaluate Access

Next Topic: Sample Policies for Suppression and Summarization Rules

Sample Policies for Custom Integrations

You can give non-Administrators the ability to create custom integrations by creating one custom role, one CALM policy, and one scoping policy. You can give other non-Administrators the ability to view custom integrations by creating an additional custom role with an associated scoping policy. You add both custom roles to the CALM Application Access policy and assign users to these roles.

The following example procedure shows you how to do this:

  1. Create an application user group called Create-DM-XMP-Files.
  2. Create an application user group called View-DM-XMP-Files.
  3. Grant Create-DM-XMP-Files and View-DM-XMP-Files access to the CA Enterprise Log Manager product.

    Grant the read and write groups access to the application.

  4. Create a CALM policy that grants Create-DM-XMP-Files the ability to create data mapping files and message parsing files using common event grammar while logged on to CA Enterprise Log Manager.

    Create the Integration-Create-Edit policy.

  5. Create a scoping policy that grants Create-DM-XMP-Files the ability to edit and view the custom DM files and XMP file saved to the EEM folder /CALM_Configuration/Content/Mapping or /CALM_Configuration/Content/Parsing using common event grammar.

    Create the Integration-Create-Edit policy.

    Create the filter for Edit-DM-XMP-Files iwth CEG policy.

  6. Create a scoping policy that grants View-DM-XMP-Files the ability to view the custom DM files and XMP file saved to the EEM folder /CALM_Configuration/Content/Mapping or /CALM_Configuration/Content/Parsing.

    Note: The CEG policy grants all Identities rights to view the Common Event Grammar.

    Create the view-DM-XMP-Files policy.

    Create filter for View-DM-XMP-Files policy.

  7. Test the policies.
  8. Assign users to both Create-DM-XMP-Files and View-DM-XMP-Files.

More information:

Create an Application User Group (Role)

Grant a Custom Role Access to CA Enterprise Log Manager

Test a New Policy

Assign a Role to a Global User