<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267744#M2072</link>
    <description>&lt;P&gt;From your statement it is not completely clear on what you are trying to achieve, if your trying to split the ES product such that users see different data within different dashboards, then I don't think that is going to be possible.&lt;/P&gt;

&lt;P&gt;If you want to allow users to have reports of their subsection of the data, then that would be possible.&lt;/P&gt;

&lt;P&gt;To explain my answer a little bit further, the data models used within ES are going to either be accessible or not accessible to particular Splunk roles. If a user has access to the data model they see what is within the data model.&lt;/P&gt;

&lt;P&gt;If your referring to data in indexes you can restrict which roles have access to the index, but this would be normal Splunk, not specific to the ES app itself. You could also potentially use search filters to provide some level of restriction on which roles can see which parts of the index although this has limitations.&lt;/P&gt;

&lt;P&gt;If you need to have different views of the ES application then I think the best you could do would be to build multiple search heads (or search head clusters), and have them look at different indexes. However this would mean that you no longer have a single ES with all security data visible..&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2016 07:52:23 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2016-10-21T07:52:23Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267743#M2071</link>
      <description>&lt;P&gt;Hello everybody. &lt;/P&gt;

&lt;P&gt;I deployed a Splunk Enterprise Security in a distributed environment for our customer. He also has many customers and he doesn't want to see all the logs together. I've heard ES does not support multi-tenant natively, but at the moment, he wants to have separable reports for customer or see in the dashboard which data belongs to whom. &lt;/P&gt;

&lt;P&gt;I don't know if there is a way to reach that. If you know, I will appreciate any help. &lt;/P&gt;

&lt;P&gt;I've been looking for something similar and I got this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/236674/security-app-with-multi-tentant.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/236674/security-app-with-multi-tentant.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 21:00:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267743#M2071</guid>
      <dc:creator>jrballesteros05</dc:creator>
      <dc:date>2016-10-20T21:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267744#M2072</link>
      <description>&lt;P&gt;From your statement it is not completely clear on what you are trying to achieve, if your trying to split the ES product such that users see different data within different dashboards, then I don't think that is going to be possible.&lt;/P&gt;

&lt;P&gt;If you want to allow users to have reports of their subsection of the data, then that would be possible.&lt;/P&gt;

&lt;P&gt;To explain my answer a little bit further, the data models used within ES are going to either be accessible or not accessible to particular Splunk roles. If a user has access to the data model they see what is within the data model.&lt;/P&gt;

&lt;P&gt;If your referring to data in indexes you can restrict which roles have access to the index, but this would be normal Splunk, not specific to the ES app itself. You could also potentially use search filters to provide some level of restriction on which roles can see which parts of the index although this has limitations.&lt;/P&gt;

&lt;P&gt;If you need to have different views of the ES application then I think the best you could do would be to build multiple search heads (or search head clusters), and have them look at different indexes. However this would mean that you no longer have a single ES with all security data visible..&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 07:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267744#M2072</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-10-21T07:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267745#M2073</link>
      <description>&lt;P&gt;The Splunk App for Enterprise Security is not supported in a multi-tenant environment at this time.  We do have many service providers running Splunk Enterprise to support multiple customers within one Splunk instance.  With the App for ES you would need to spin up a separate instance for each customer.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 14:44:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267745#M2073</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2016-10-21T14:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267746#M2074</link>
      <description>&lt;P&gt;Hello, thanks for your reply :). &lt;/P&gt;

&lt;P&gt;I asked to many people and everybody says I will need a separate instance for each customer, like you said in your first answer. &lt;/P&gt;

&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 15:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267746#M2074</guid>
      <dc:creator>jrballesteros05</dc:creator>
      <dc:date>2016-10-24T15:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267747#M2075</link>
      <description>&lt;P&gt;The Mothership app may possibly be of use for the above described scenario. &lt;A href="https://splunkbase.splunk.com/app/4646/"&gt;https://splunkbase.splunk.com/app/4646/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2019 21:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267747#M2075</guid>
      <dc:creator>Doc_Yes</dc:creator>
      <dc:date>2019-08-17T21:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267748#M2076</link>
      <description>&lt;P&gt;Hi everyone, it's there any progress about multi-tenant with ES?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 13:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267748#M2076</guid>
      <dc:creator>rsulek</dc:creator>
      <dc:date>2020-02-11T13:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267749#M2077</link>
      <description>&lt;P&gt;No, there hasn't.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 15:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267749#M2077</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-02-11T15:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267750#M2078</link>
      <description>&lt;P&gt;I would suggest splitting on SH only, while all the indexes will have to be customized.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 16:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/267750#M2078</guid>
      <dc:creator>dolezelk</dc:creator>
      <dc:date>2020-02-17T16:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/702462#M12133</link>
      <description>&lt;P&gt;Since your last update on 21 Oct 2016 stating that Splunk Enterprise Security does not support multi-tenancy, what is the status right now? Does Splunk Enterprise Security is now support multi-tenancy?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 02:33:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/702462#M12133</guid>
      <dc:creator>mohdfadhlan</dc:creator>
      <dc:date>2024-10-22T02:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to implement multi-tenancy in a distributed search environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/702477#M12136</link>
      <description>&lt;P&gt;Status is unchanged. Splunk ES is still long way from having multi tenancy supported as it is. Request for multi-tenancy is marked as "Future prospect" at Splunk Ideas portal:&amp;nbsp;&lt;A href="https://ideas.splunk.com/ideas/EID-I-30" target="_blank"&gt;Add native multi-tenancy capability to Enterprise Security | Ideas&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 07:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-implement-multi/m-p/702477#M12136</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2024-10-22T07:12:43Z</dc:date>
    </item>
  </channel>
</rss>

