User Operations

Topics

Password Management

For Native Authentication Users:

Administrator Reset:

  1. Select user account

  2. Click Reset Password

  3. Generate temporary password

  4. Send credentials via secure channel

  5. Force password change on next login

Self-Service Reset:

  1. User clicks Forgot Password on login page

  2. Enter username/email

  3. Follow email instructions

  4. Create new password meeting policy requirements

Password Policy Configuration:

  • Minimum length: 8-20 characters

  • Complexity: uppercase, lowercase, numbers, symbols

  • History: 5-10 previous passwords

  • Expiration: 30-180 days

  • Lockout: 3-10 failed attempts

Account Management

Account Lockout Recovery:

  1. Navigate to User ManagementLocked Accounts

  2. Review lockout reason and timestamp

  3. Verify user identity through alternative channel

  4. Click Unlock Account

  5. Reset password if security incident suspected

  6. Document unlock reason for audit

Temporary Access Grants:

curl -X POST "https://els-console:9200/api/v1/users/john.doe/elevate" \
  -H "Authorization: Bearer API_KEY" \
  -d '{
    "elevated_role": "incident_commander",
    "duration_hours": 8,
    "justification": "Security incident INC-2024-001",
    "auto_revoke": true
  }'

API Key Management

Generate API Key:

  1. Navigate to API ManagementGenerate New Key

  2. Configure:

    • Name: Descriptive identifier

    • Scope: Specific permissions

    • Expiration: 30-365 days

    • Rate Limits: Requests per minute

    • IP Restrictions: Allowed source IPs

Key Security:

curl -H "Authorization: Bearer YOUR_API_KEY" \
     -H "Content-Type: application/json" \
     "https://els-console:9200/api/v1/alerts?status=open"

Rate Limiting Configuration:

  • Default: 100 requests/minute

  • Search operations: 10 requests/minute

  • Data export: 5 requests/hour

  • Administrative operations: 1000 requests/minute