Multitenancy in Network Threat Analytics
The IBM® QRadar® Network Threat Analytics (NTA) app supports multitenant environments in QRadar 7.6.0 and later, when used with QRadar Network Threat Analytics 2.0.0 or later.
Multitenant environments enable Managed Security Service Providers (MSSPs) and multi-divisional organizations to provide security services to multiple client organizations from a single, shared NTA deployment. There is no need to deploy a unique QRadar Network Threat Analytics instance for each customer.
You can create multiple tenant instances from a single deployment, rather than managing multiple deployments. For example, as an MSSP partner, you might host 20 clients on a single instance of NTA, with each client managing network traffic analysis for their specific environment.
Overview
Deployment guidance
The number of NTA instances that are supported is directly related to the QRadar environment. In general, tenants must be added one at a time and after each addition, you must verify that QRadar is working correctly and the remaining apps are also working as expected. This approach helps ensure system stability and allows for proper monitoring of resource usage.
QRadar system performance is validated by using a standard deployment that supports multiple NTA tenant application instances. The standard configuration consists of a console, an App Host, an Event Processor using up to 90% of the licensed EPS capacity, and a Flow Processor using up to 90% of the licensed FPM capacity.
QRadar admin or MSSP admin role
Security profiles
NTA does not support multiple domains under one security profile. A security profile can be associated with only a single domain to help ensure that NTA operates correctly.
Moving from a single instance of NTA to multiple instances
If you are moving from a single instance of NTA to a multitenant setup, the first instance is a shared instance. After 30 minutes of creating a second instance of NTA in QRadar, the first shared NTA instance changes into an admin instance.
Warnings
Set up your multitenant environment as specified or you might experience problems with NTA. Consider the following warnings:
- Do not uninstall the admin or shared instance.
- Each instance can have only a single tenant and each tenant can have only a single domain.
- Tenants cannot be provided an admin authorized service token.
- Network flow data sources must be properly configured for each tenant.
- Proper network segmentation must be there to help ensure tenant data isolation.