All Apps and Add-ons

Splunk Security Essentials: Segregation/Multi-tenancy: How would you approach adding multi-tenancy to SSE?

joostdecock
Observer

TL;DR: How would you approach adding multi-tenancy to SSE?

Hi there,

I am looking to use the Splunk Security Essentials (SSE) app on a search head (SH) that is peered with a bunch of other SHs that have their own data.

The app works fine, but it throws all the data it can find onto one pile and does its thing.

What I'd like is to be able to set a SSE-wide extra query constraint (splunk_server=whatever) so that it would only look at data from that peered SH.
This applies both to the original introspection, as well as the subsequent reports, and mapping to the MITRE framework.

Best case scenario, I can add a drop-down to select the peer and now the app would work with data from that peer.
Alternatively, I guess I could deploy a modified app for each peer that is then configured to look at that data only.

I'm relatively new to Splunk ( hi :wave: ) but not so new to development, so I'm happy to roll up my sleeves.

I was hoping that perhaps somebody with a good understanding of the app (there's a lot going on) could give me some pointers on the best way to tackle this.


thanks in advance for your input, much appreciated  : )
joost

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I treat SSE as a cookbook.  I use it to get example SPL and then build my own searches from it.  When you build your own SPL, include code to isolate searches to the desired tenant.

---
If this reply helps you, Karma would be appreciated.
0 Karma

joostdecock
Observer

Thank you @richgalloway for your input.

That is certainly good advice, and indeed always an option.
I'd like to integrate it into that app though, so operators can use it that way.

So I'm hoping somebody with more insight into that app itself has some pointers : )

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...