All Apps and Add-ons

How to achieve Multi Tenancy in Splunk UBA and Splunk ES

ashishmaind2499
New Member

How to achieve multi-tenancy in Splunk UBA and ES?

0 Karma

cmeisch
Path Finder

Bringing this back to life:

1) It looks like with ES 6.4, Splunk brought the solution of Entity Zones.   I personally have not played with it yet but will be very soon.  https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Entityzones

So at first glance this looks like the solution if you are just playing with ES.  Now we bring in the big wrench like UBA.  I have not found yet a solution to have multiple tenants going into one UBA.  You will have ip overlap issue... 

Has anyone have more to add to this and\or do we know if there is a solution or one coming down the pipe?

0 Karma

starcher
Influencer

There is no multi-tenancy in ES.

0 Karma

ashishmaind2499
New Member

@starcher then any workaround to achieve this? Can we edit ES searches and keep separate index per customer and restrict data access using user roles?

0 Karma

starcher
Influencer

No there is no easy way to create borders in ES. Hence there not being multi tenant already. I don't know UBA. You should ask your sales rep and they can arrange more specific calls with appropriate Splunk product specialists.

0 Karma

ashishmaind2499
New Member

Also how the case differs with UBA?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...