Page 2 of 4
Re: Acknowledge a problem as.
Posted: Wed Sep 18, 2013 2:08 pm
by abrist
Thanks, Bandit.
Re: Acknowledge a problem as.
Posted: Tue Oct 08, 2013 9:49 am
by BanditBBS
Sorry for reviving a slightly dead thread.....but.......
This is becoming extremely important in my environment. I am about to install my 4th or 5th(is it bad I lost count?) XI server and I really want people to only see what they should see on each server in Fusion and also be logged into XI as themselves when drilling down. I know this will cause slowness, but I really think this should be an option (don't force others if happy with current method). I spoke to Ethan and maybe a couple others about this at the conference and they said it was doable, would just cause a slowness. I'm not a religious man, but this is one of the couple feature requests I am praying gets implemented (Soon

)
Re: Acknowledge a problem as.
Posted: Tue Oct 08, 2013 2:42 pm
by lmiltchev
We got it, BanditBBS. It may take a while, though.
Re: Acknowledge a problem as.
Posted: Tue Jan 20, 2015 4:36 pm
by TBT
At present time, the current state of Fusion is proving to be difficult to use and administer in a multi-user environment.
I'd like to re-establish dialog on this request which was started back on Dec 7th, 2012. Other organizations have expressed interest in this functionality and several others are following Tracker ID:
http://tracker.nagios.com/view.php?id=436 progress.
Perhaps we should outline what is required?
Re: Acknowledge a problem as.
Posted: Tue Jan 20, 2015 5:53 pm
by abrist
TBT wrote:Perhaps we should outline what is required?
Please do, though I bet we could guess. I did ping Scott about this again as well.
Re: Acknowledge a problem as.
Posted: Wed Jan 21, 2015 1:18 pm
by abrist
TBT wrote:Perhaps we should outline what is required?
I got a bit of traction from the devs. Can you list your requirements (be very, very much so verbose in the extreme

)?
Re: Acknowledge a problem as.
Posted: Wed Jan 21, 2015 1:41 pm
by BanditBBS
This is my input, he can of course add his own as well.......
My desires are only these two items, short list, but I realize may not be very easy, but to make fusion usable at all it is needed.
1.)When logging into Fusion, only see what your ID is actually able to see on the downstream XI servers
2.)When clicking through on something, get logged into XI as your proper user
Re: Acknowledge a problem as.
Posted: Wed Jan 21, 2015 2:13 pm
by TBT
BanditBBS wrote:This is my input, he can of course add his own as well.......
My desires are only these two items, short list, but I realize may not be very easy, but to make fusion usable at all it is needed.
1.)When logging into Fusion, only see what your ID is actually able to see on the downstream XI servers
2.)When clicking through on something, get logged into XI as your proper user
BanditBBS, a few comments on your items if I may.
1. Makes it difficult to administer a large number of users across multiple XI servers.
2. You hit the nail on the head. This is similar to how I envision it (See my post below).
Re: Acknowledge a problem as.
Posted: Wed Jan 21, 2015 2:16 pm
by TBT
Our organization has a large user base with Nagios Fusion acting as a central location to manage users who monitor network elements across all XI severs. The accounts we've created in Nagios Fusion have an Authorization Level of User (Read-only) with the purpose of monitoring and acknowledging. The accounts created in Nagios XI have an Authorization Level of Admin with the purpose of maintaining elements that everyone within the organization can view and interact with.
Currently Nagios Fusion user permissions are managed locally. Once authorized, said user also gains authorization level of the roll account (fusion-admin) when interacting with any fused XI servers. Which is fine if users only view information, but problematic for accountability on actions like acknowledgment as the user is "Logged in as: fusion".
We would like the following changes be taken into consideration when users (UID) interact with fused XI servers through Fusion:
1. If UID present on XI server then inherit credentials for this session.
2. If UID NOT present on XI server then assume Fusion roll account (fusion-admin) credentials, but all interactions (eg: acknowledgments) are accounted for as UID.
3. Also as introduced in XI 2014R2.0, Add user Auth Level column to users table to see user levels from the main manage users page with Fusion.
Re: Acknowledge a problem as.
Posted: Wed Jan 21, 2015 2:21 pm
by BanditBBS
TBT wrote:BanditBBS wrote:This is my input, he can of course add his own as well.......
My desires are only these two items, short list, but I realize may not be very easy, but to make fusion usable at all it is needed.
1.)When logging into Fusion, only see what your ID is actually able to see on the downstream XI servers
2.)When clicking through on something, get logged into XI as your proper user
BanditBBS, a few comments on your items if I may.
1. Makes it difficult to administer a large number of users across multiple XI servers.
2. You hit the nail on the head. This is similar to how I envision it (See my post below).
My turn
1.) We are a hosting/managed services company and have multiple customers located on our XI servers. They can not see eachother's stuff. We also have DBAs that only see the customers they handle. So fi spread across two XI servers and wanting to use Fusion for a single pane of glass, only seeing what they are configured to see in the XI servers is mandatory or we just can't use it. At my old job(American Eagle) seeing everything wouldn't be an issue because everyone worked for the same company.
2.) I'm good like that, lol
There has to be a middle ground that can make everyone happy