cancel
Showing results for 
Search instead for 
Did you mean: 

Multi Tenancy for 2 divisions of the same company

We have 2 different companies of same group. Data sources of both companies will be monitored from one SOC. Our concern is how to keep event logs separate without mixing them. We have ESM, ELM & a common Receiver.

Please suggest.

Regards

Prashant Ketkar

3 Replies
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Multi Tenancy for 2 divisions of the same company

Please look into zones. They serve as a container that can be associated to subnets and devices. Zones support overlapping IP space and role-based access.

Re: Multi Tenancy for 2 divisions of the same company

Dear Andy

Thanks for your reply and the document you have provided. I have a further query. Can we relate Zones in ESM, Storage Pools in ELM, Storage in DAS.

Regards

Prashant

McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 4

Re: Multi Tenancy for 2 divisions of the same company

Zones extend for all ESM data (including if there is a DAS with the ESM). The ELM data is accessible for each event under the ELM tab but users will need to restricted from full ELM query capability.

elm-events.PNG