All Apps and Add-ons

How to achieve Multi Tenancy in Splunk UBA and Splunk ES

ashishmaind2499
New Member

How to achieve multi-tenancy in Splunk UBA and ES?

0 Karma

cmeisch
Path Finder

Bringing this back to life:

1) It looks like with ES 6.4, Splunk brought the solution of Entity Zones.   I personally have not played with it yet but will be very soon.  https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Entityzones

So at first glance this looks like the solution if you are just playing with ES.  Now we bring in the big wrench like UBA.  I have not found yet a solution to have multiple tenants going into one UBA.  You will have ip overlap issue... 

Has anyone have more to add to this and\or do we know if there is a solution or one coming down the pipe?

0 Karma

starcher
Influencer

There is no multi-tenancy in ES.

0 Karma

ashishmaind2499
New Member

@starcher then any workaround to achieve this? Can we edit ES searches and keep separate index per customer and restrict data access using user roles?

0 Karma

starcher
Influencer

No there is no easy way to create borders in ES. Hence there not being multi tenant already. I don't know UBA. You should ask your sales rep and they can arrange more specific calls with appropriate Splunk product specialists.

0 Karma

ashishmaind2499
New Member

Also how the case differs with UBA?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...