All Apps and Add-ons

How to achieve Multi Tenancy in Splunk UBA and Splunk ES

ashishmaind2499
New Member

How to achieve multi-tenancy in Splunk UBA and ES?

0 Karma

cmeisch
Path Finder

Bringing this back to life:

1) It looks like with ES 6.4, Splunk brought the solution of Entity Zones.   I personally have not played with it yet but will be very soon.  https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Entityzones

So at first glance this looks like the solution if you are just playing with ES.  Now we bring in the big wrench like UBA.  I have not found yet a solution to have multiple tenants going into one UBA.  You will have ip overlap issue... 

Has anyone have more to add to this and\or do we know if there is a solution or one coming down the pipe?

0 Karma

starcher
Influencer

There is no multi-tenancy in ES.

0 Karma

ashishmaind2499
New Member

@starcher then any workaround to achieve this? Can we edit ES searches and keep separate index per customer and restrict data access using user roles?

0 Karma

starcher
Influencer

No there is no easy way to create borders in ES. Hence there not being multi tenant already. I don't know UBA. You should ask your sales rep and they can arrange more specific calls with appropriate Splunk product specialists.

0 Karma

ashishmaind2499
New Member

Also how the case differs with UBA?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...