Installing and configuring NTA instances to support multitenancy

Install and configure multiple IBM® QRadar® Network Threat Analytics (NTA) instances to support a multitenant environment in QRadar.

Before you begin

  • Complete all steps in the QRadar configurations section.
  • Ensure IBM QRadar Hub app 3.0.0 or later is installed with QRadar 7.6.0 or later.
  • Before you configure any NTA instance, make sure that you have an admin instance of NTA installed by completing the steps in Installing the QRadar Network Threat Analytics app.
Attention: Do not uninstall the admin or shared instance.

About this task

QRadar admin or the MSSP admin must complete the following procedure.

Procedure

  1. From the IBM QRadar Hub app, find the QRadar Network Threat Analytics extension.
    Screenshot of IBM QRadar Hub app showing the Network Threat Analytics extension
  2. Select Options > Create new instance.
  3. Choose the security profile for the instance and click Next.
    Note: If no instances are created, create an admin or shared instance first. If admin or shared instance is available, create the first tenant instance. If the tenant security profile is not listed, ensure that you create a security profile and deployed changes.
  4. Associate the app to any other roles that are listed and click Next.
  5. Review the summary and click Confirm and Create.
  6. After the instance is created, select the instance and then click Options > Configure Instance > NTA Settings.
  7. On the NTA Settings page, add the Authorized service token for the tenant admin that is responsible for the instance of NTA.
    Note: Make sure to choose the correct token.
  8. Save the configuration.
  9. Repeat these steps for all instances of NTA that you want.