Skip to main content


Hello Secopians, I have a question, I have assigned a Chronicle Service admin permission to one of my team member. Still he is getting this permission issue


Missing permissions:


chroniclesm.gcpLogFlowFilters.get


I'm sure that this permission isn't somewhere in GCP IAM roles & attached permissions. Can someone help me understand where is this coming from? is this something that need to be manage for chronicle SecOps tenant side for our org env?



OR Does it require Org admin permission to Manage it?




Any assistance would be greatly appreciated.


After troubleshooting, found that this is the permission that was missing from the
Chronicle Service Admin
role policy. We have to custom add it by creating custom role from Chronicle service admin. No where in the documentation, it is mentioned about the chronicle log filters permissions.



Hi
@spawar_apex
thank you for the feedback, I have forwarded it to the team.



Opened bug 291561756 to investigate this issue. Thanks for letting us know!



Thanks
@shakedtal
&
@adam9
for your quick response & taking action to remediate.


Reply