Multitenancy in Network Threat Analytics

The IBM® QRadar® Network Threat Analytics (NTA) app supports multitenant environments in QRadar 7.6.0 and later, when used with QRadar Network Threat Analytics 2.0.0 or later.

Multitenant environments enable Managed Security Service Providers (MSSPs) and multi-divisional organizations to provide security services to multiple client organizations from a single, shared NTA deployment. There is no need to deploy a unique QRadar Network Threat Analytics instance for each customer.

You can create multiple tenant instances from a single deployment, rather than managing multiple deployments. For example, as an MSSP partner, you might host 20 clients on a single instance of NTA, with each client managing network traffic analysis for their specific environment.

Important: When you log in to NTA as an MT site administrator, two tenants are displayed by default, one of which is the Admin tenant. Use the IBM QRadar Hub app to configure which additional tenant is shown by default.

Overview

Multitenancy in NTA requires the QRadar administrator or an MSSP administrator to complete several setup procedures that include specific configuration tasks. The QRadar admin must use the QRadar Hub app 3.0 or later to install and configure the first or shared NTA instance and the additional non-admin or tenant instances. After the non-admin instances are established, the QRadar admin must also assign user roles and specific permissions. The user roles for the non-admin instances include NTA tenant admin and NTA tenant users. The following figure explain the multitenancy in IBM QRadar.
Diagram showing the QRadar NTA multitenancy setup

Deployment guidance

The number of NTA instances that are supported is directly related to the QRadar environment. In general, tenants must be added one at a time and after each addition, you must verify that QRadar is working correctly and the remaining apps are also working as expected. This approach helps ensure system stability and allows for proper monitoring of resource usage.

QRadar system performance is validated by using a standard deployment that supports multiple NTA tenant application instances. The standard configuration consists of a console, an App Host, an Event Processor using up to 90% of the licensed EPS capacity, and a Flow Processor using up to 90% of the licensed FPM capacity.

The guidelines help ensure the proper functioning of your QRadar system and NTA. If errors are encountered within your QRadar environment, consider increasing RAM or adding more Event Processors or Flow Processors. Monitor CPU utilization during processing phases and verify adequate disk space for baseline creation and ongoing operations to maintain optimal performance.
Note: As a general guideline, each NTA tenant requires 4 GB of RAM. Before you add more tenants, ensure that the App Host has sufficient available RAM and disk space. The total number of tenants that can be supported depends on the available system resources, including RAM and disk space and the overall capacity of your QRadar infrastructure.

QRadar admin or MSSP admin role

Important: The QRadar admin must set up the first or admin instance of NTA. After the admin instance of NTA is established with an admin token and network baseline that is created, more NTA instances can then be created. When you run multiple instances of NTA, the admin instance is used only to uninstall and install instances. Do not remove the admin instance.

Security profiles

NTA does not support multiple domains under one security profile. A security profile can be associated with only a single domain to help ensure that NTA operates correctly.

Moving from a single instance of NTA to multiple instances

If you are moving from a single instance of NTA to a multitenant setup, the first instance is a shared instance. After 30 minutes of creating a second instance of NTA in QRadar, the first shared NTA instance changes into an admin instance.

Warnings

Set up your multitenant environment as specified or you might experience problems with NTA. Consider the following warnings:

  • Do not uninstall the admin or shared instance.
  • Each instance can have only a single tenant and each tenant can have only a single domain.
  • Tenants cannot be provided an admin authorized service token.
  • Network flow data sources must be properly configured for each tenant.
  • Proper network segmentation must be there to help ensure tenant data isolation.