We recommend reviewing what is submitted before posting, in case your idea has already been submitted by another community member. If it has been submitted, vote for that existing feature request (by clicking the up arrow) to increase its opportunity of being added to Cireson solutions.
For more information around feature requests in the Cireson Community click here.
Comments
The service account should be hidden under History log. Huge security exposure there.
One issue that would arise here is the number of service accounts and their names.
Would it be an acceptable solution just to remove any of the service accounts that are identified within SCSM? (Workflow, Connectors, Orchestrator etc.) ?
Or would it be required to have a pattern match? (SVC_%) etc.
The latter would cover the Orchestrator runbook service account, which (AFAIK) doesn't have SCSM-level permissions, but can manipulate objects.
Orchestrator service account would not write to the log, but the account used to access SCSM IP from Orch would.
I'd be interested to hear if others would also be able to live with a pattern match on accounts.
I know all my service accounts have always had a specific naming convention (svc_%) but not sure about the wider community.
Please post your preference to this thread so we can gauge feedback from the widest possible group.
In the meantime, hiding accounts with the username 'svc-' or similar would be great to include as an option in the 'Settings Items' page in the Admin Settings.
Or just being able to hide comments with a certain Title such as "The review activity votes were processed" or "There was a status change for activity". These are pretty nonsensical to an end user (even to analysts)
New Account to Exclude) would be pretty fantastic. Although a single pattern match would suffice as a v1.
No update on this other than the more votes we get for this the higher up the order it will go for our development team to include it in a development sprint in the future.
In the mean time, you could hide the comment from the end user (Security by Obscurity) by developing some custom CSS or JS code that would just hide the comments that are entered by the target accounts.
Or has anyone got any custom css / js they can share that does this?
There has been an upload to the community download section for this kind of modification: https://community.cireson.com/discussion/1861/custom-expanded-action-log-comments