IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only

Introducing NTA Multi-Tenancy in IBM QRadar

By Sambhav Sahoo posted 30 days ago

  

Customers running shared security environments have been asking for a better way to use QRadar Network Threat Analytics across multiple tenants. With the launch of NTA Multi-Tenancy, we are addressing that need by enabling tenant-aware analytics within a shared QRadar deployment.

This capability is designed for MSSPs, large enterprises, and financial institutions that operate QRadar across multiple customers, business units, or internal teams. It helps these organizations use NTA with stronger separation of analytics and detections per tenant.

A quick view of NTA

QRadar Network Threat Analytics, or NTA, analyzes network flow data to identify suspicious or abnormal traffic patterns. It helps security teams detect behavior that may not be visible through logs alone.

For example, NTA can help surface unusual communication patterns, activity that may indicate lateral movement, and deviations from expected network behavior. It adds another layer of visibility to QRadar by focusing on how systems communicate across the network.

Why multi-tenancy matters

Many MSSPs and large enterprises already use QRadar in multi-tenant environments. In these deployments, a single QRadar instance may support multiple customers or business units.

Until now, this created a gap for NTA. Customers needed analytics and detections to remain separated by tenant so that one tenant’s network behavior would not influence another tenant’s results. Without that separation, customers had limited confidence in using NTA at scale in shared environments.

This feedback came through customer conversations, Ideas portal input, and discussions with teams supporting MSSPs, banks, financial institutions, and large enterprises.

What is new

NTA Multi-Tenancy allows analytics and detections to run independently for each tenant within a shared QRadar deployment.

The feature focuses on three core areas:

  • Tenant-isolated analytics execution

  • Support for shared QRadar deployments

  • Alignment with QRadar tenant management

This means each tenant’s analytics are based on its own network data. It also helps reduce the need for separate NTA deployments or manual workarounds in shared environments.

How customers benefit

For customers, the value is practical.

First, it improves detection confidence. Analytics are scoped to the tenant, which helps reduce cross-tenant influence and improves trust in the detections.

Second, it supports operational scale. MSSPs and large enterprises can use NTA across multiple tenants while continuing to operate within a shared QRadar environment.

Third, it aligns NTA more closely with how customers already use QRadar. For organizations that have standardized on QRadar as a shared security platform, this makes NTA easier to adopt in the same operating model.

Who should look at this feature

This feature is most relevant for:

  • MSSPs managing multiple customer environments

  • Financial institutions with multiple business units or segmented environments

  • Large enterprises running shared security operations

  • Customers that require tenant-level separation for analytics and detections

If your organization already uses QRadar in a multi-tenant setup, NTA Multi-Tenancy can help extend network threat analytics into that environment with clearer separation between tenants.

What this means for QRadar customers

NTA Multi-Tenancy is an important step in making network threat analytics more usable in shared environments. It closes a known gap for customers that wanted to adopt NTA but needed tenant-aware analytics before moving forward.

From a product perspective, this launch is about making NTA fit better into real customer deployments. Customers should be able to scale network analytics across tenants without losing confidence in data separation, detection accuracy, or operational control.

Getting started

Customers interested in NTA Multi-Tenancy should review the QRadar Network Threat Analytics app documentation for version availability, deployment requirements, and configuration guidance. You can also work with your IBM representative or support team to understand how this capability applies to your environment.

We look forward to customer feedback as teams begin using NTA Multi-Tenancy in shared QRadar deployments.

0 comments
15 views

Permalink