QRadar configurations for setting up multitenancy in NTA

Configure QRadar® 7.6.0. or later to support IBM® QRadar Network Threat Analytics (NTA) 2.0.0 or later in a multitenant environment.

You must have QRadar administrator privileges to set up your multitenant environment. For more information, see QRadar administration documentation.

For more information about multitenancy in QRadar, see Multitenant management.

Note: To configure NTA multitenancy, admin must configure NTA with network baseline created.

Configuration steps

The following table outlines the steps that must be completed before you configure your NTA instances. The steps that are outlined in the table are run from the QRadar admin settings.

Step Action Details
1 Define flow sources Create flow source for each domain in System Configuration > Data Sources > Flow Sources. Each domain requires its own flow source for each NTA instance to function properly.
Note: Duplicate or shared flow sources per tenant must not be shared across domains. If they are shared, they might fall into the default domain.
2 Define log sources
  1. Create log source for each security profile in Log Sources > Log Source Manage Log Sources > New Log Source > Single Log Source.
  2. Select Log source type as IBM QRadar Network Threat Analytics.
  3. Select the protocol type as Syslog.
  4. To configure log source parameters, enter the proper Log Source Name.
  5. To configure protocol parameters, add a log source identifier by using the following format:
    ibm-nta-analytics.qrapp.local.{your-security-profile-name}
    for example, ibm-nta-analytics.qrapp.local.finance-sp
  6. To save the configuration, click + (Add) option and click Finish.
  7. Repeat the process to create a log source for each security profile that requires multitenancy support.
3 Define tenants In System Configuration > User Management > Tenant Management, create a set of tenants (for example, TenantA, TenantB). For more information, see Provisioning a new tenant.
4 Define domains In System Configuration > Domain Management, create domains and associate the Flow Source from step 1 (if flow source is not used can also associate Flow Collector and Flow VLAN IDs).
Note:
  • Flows can be domain-tagged based on specific VLAN IDs (Enterprise and Customer VLAN) assigned to that domain.
  • Flows can be domain-tagged by assigning defined flow sources (for example, NetFlow or IPFIX) to a domain.
  • Flows can be domain-tagged by assigning a flow collector to a domain, which applies that domain to all flows it receives.
For more information, see Creating domains.
5 Define networks (optional) In System Configuration > Network Hierarchy, define network hierarchies if you want each tenant to have a specific network hierarchy. For more information, see Network hierarchy updates in a multitenant deployment.
6 Create security profiles In System Configuration > User Management > Security Profiles, create a profile for each domain. Associate the previously defined domain, log source or log source group, and network.
Note: Domain assignments take precedence over all settings on the Permission Precedence, Networks, and Log Sources tabs.
For more information, see Security profiles.
7 Create user roles In System Configuration > User Management > User Roles, create roles and deploy changes:
  • QRadar admin or MSSP admin: Install and configure each NTA instance
  • Tenant admin: NTA Admin role with delegated administration permissions
  • Tenant User: NTA Analyst role for reviewing data
For more information, see Creating a User role.
8 Create authorized service tokens In System Configuration > User Management > Authorized Services, create service tokens. Associate each token to the profile from step 5 and role from step 6. Each tenant admin requires an authorized service token. For more information, see Creating authorized service token.
9 Create users In System Configuration > User Management > Users, create tenant admin and tenant users. Associate each to the specific role, profile, and tenant. For more information, see Creating a user account.
10 Deploy changes On the Admin tab, click Deploy changes.

Configuration diagram

The following diagram illustrates the configuration steps:

Diagram showing the QRadar configuration steps for NTA multitenancy setup