hana02:~ # crm configure
crm(live/hana02)configure# role monitor read xpath:"/cib"
crm(live/hana02)configure# acl_target hawk-aduser monitor # this will add user read-only
crm(live/hana02)configure# show
crm(live/hana02)configure# commit
- login in hawk, and user is read-only
https://documentation.suse.com/sle-ha/11-SP4/html/SLE-ha-all/cha-ha-acl.html#sec-ha-acl-basics