Discovery and Modeling Spectrum user configuration
search cancel

Discovery and Modeling Spectrum user configuration

book

Article ID: 435575

calendar_today

Updated On:

Products

Network Observability Spectrum

Issue/Introduction

Is that a way to provide Discovery rights to the user without admin full rights?

Provide Discovery Rights Without Full Admin Access in Spectrum

Need to provide Discovery rights to a user without granting full administrative privileges in Spectrum․​​​​

CONTEXT: Configuring restricted user access in OneClick

IMPACT: Administrators cannot securely delegate specific Discovery and Modeling tasks

Environment

Network Observability DX NetOps Spectrum Discovery

Resolution

PREREQUISITES:

  • OneClick Administrator access

STEPS:

Step 1․ CREATE DISCOVERY PRIVILEGE ROLE

Path: Users tab -> Roles tab -> New

Create a specific Admin level Privilege Role with only Discovery options allowed․ Check the following privileges:

  • Discovery Console: Grants access to the tool

  • Create/Modify Discovery Configurations: Allows saving and editing IP ranges and schedules

  • Execute Discovery: Allows clicking Discover or Run

  • Modeling (Optional but Recommended): Required to add discovered devices to Topology

EXPECTED: Role contains only Discovery and Modeling rights

Step 2․ CREATE OPERATOR PRIVILEGE ROLE

Path: Users tab -> Roles tab -> New

Create a specific Operator level Privilege Role with all other necessary options․

EXPECTED: Role contains standard operational rights

Step 3․ ASSIGN ROLES TO USER

Path: Users tab -> Access tab

Assign the specific roles to the user instead of default roles․

EXPECTED: Privileges area shows Operator Only for everything except Discovery

VERIFY SUCCESS:

In the Access -> Privileges area we should see Operator Only for everything except Discovery.

Step 4․ CONFIGURE CLI ACCESS (IF NEEDED)

Command: Edit the ․hostrc file

Ensure the user is appropriately configured in the ․hostrc file if CLI tools are needed․

EXPECTED: CLI tools function correctly for the user

VERIFY SUCCESS:

  • User can manage discovery profiles and run jobs

  • User cannot access global system settings