cancel
Showing results for 
Search instead for 
Did you mean: 

What does the Alert Assignment Supervisor permission do?

Under Role permissions in IPS there is an entry for Alert Assignment Supervisor, not sure what exacly gives permission to? Does anybody know? 

3 Replies
Highlighted
Reliable Contributor mjesmer
Reliable Contributor
Report Inappropriate Content
Message 2 of 4

Re: What does the Alert Assignment Supervisor permission do?

Hello Josegto123,

 

I do not see this "Role" in my base install of 9.2 NSM. Can you provide the NSM version? Is this a default role or one that your orginization created?


Regards,

 

Matthew

Reliable Contributor petermason
Reliable Contributor
Report Inappropriate Content
Message 3 of 4

Re: What does the Alert Assignment Supervisor permission do?

Hi Josegto123,

I don't see any documentation that explains what rights each of the Role Privileges grant, the only default role that I see with this Privilege is the Super User role, so you would guess it is not needed by most users.

It may be related to the Alert Assignment function available from the Other Actions menu in the Attack Log, but I'm just guessing here.

You should open an SR with Support to see if they can provide you with additional details.

@d_aloy  are you familiar with Role Permissions?

Regards

Peter Mason

McAfee Employee daloy
McAfee Employee
Report Inappropriate Content
Message 4 of 4

Re: What does the Alert Assignment Supervisor permission do?

Hi Jose(I guess!), and hey! @petermason  (Good to hear from you mate ;)!....)

You are correct - this has to do with the "Other" options available on the "Attack Log", that allows a "Super User" (i.e. the default admin account) to Assign a specific alert to a user for analysis:

https://docs.mcafee.com/bundle/network-security-platform-9.1.x-product-guide/page/GUID-6373BAE3-F15E...

On older NSM versions, when we used to have the RTTA (Real Time Threat Analyzer), we had the "Incidents" tab that was there for this function - to be able to track the analysis of specific alerts when assigned to a user. 

I have just had a look and there does not seem to be the option of tracking analysis, other than adding some comments by the analyst. I've shared this internally to check if we really need this "role" and "feature" given the current options and the fact that most analytics are performed by the SOC analysts at the SIEM level, which provides further correlation capabilities with events coming in from other products/systems/networks.

HTH.

Regards,

David

 

 

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community