All Apps and Add-ons

How to achieve Multi Tenancy in Splunk UBA and Splunk ES

ashishmaind2499
New Member

How to achieve multi-tenancy in Splunk UBA and ES?

0 Karma

cmeisch
Path Finder

Bringing this back to life:

1) It looks like with ES 6.4, Splunk brought the solution of Entity Zones.   I personally have not played with it yet but will be very soon.  https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Entityzones

So at first glance this looks like the solution if you are just playing with ES.  Now we bring in the big wrench like UBA.  I have not found yet a solution to have multiple tenants going into one UBA.  You will have ip overlap issue... 

Has anyone have more to add to this and\or do we know if there is a solution or one coming down the pipe?

0 Karma

starcher
SplunkTrust
SplunkTrust

There is no multi-tenancy in ES.

0 Karma

ashishmaind2499
New Member

@starcher then any workaround to achieve this? Can we edit ES searches and keep separate index per customer and restrict data access using user roles?

0 Karma

starcher
SplunkTrust
SplunkTrust

No there is no easy way to create borders in ES. Hence there not being multi tenant already. I don't know UBA. You should ask your sales rep and they can arrange more specific calls with appropriate Splunk product specialists.

0 Karma

ashishmaind2499
New Member

Also how the case differs with UBA?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...