Showing results for 
Search instead for 
Did you mean: 

Multi-Tenant Configuration


I was wondering what would be the best solution to manage multi-tenant configuration in a SIEM.

I've heard and read the best way to manage this would be to have a dedicated ERC for each tenant.

What about if I want to handle multiple tenants with only one ERC ? What would be the solution to identify from which tenant the logs are coming from and to apply separate parsing / correlation rules and reports considering type of logs per tenant.

Will the concept of "Zoning" can provide what I want ? For now, "Zoning" is still a bit blurry to me.

I wouldn't mind if someone can give me a clarification on this point.

Thanks and regards,


Want to Ask a Question?
Many members like to perform a search first in case other customers have already asked and answered a similar question. However, to ask a question, first select a forum then click on Post a Topic. You must sign in or log in with your existing credentials.

McAfee Service Portal customers please use your existing username and password to log into the community.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community