Skip to main content
ArcreVich
New Member
December 23, 2019
Question

adom, multi tenancy, syslog

  • December 23, 2019
  • 0 replies
  • 1980 views

Hi all

I'd like to know if is it possible to configure the FAZ this way :

We manage a bunch of devices ( switches, windows, apc ... ) from multiple companies; these devices send syslog ( or syslog-like ) messages ( actually, admin logins and logouts ) to a single splunk collector, splunk organizes them by company ( in db called "indexes" ) ; these indexes isolate company devices, so every company can only see theyr devices, providing multitenancy; no or very little processing is required on these data, they are just stored for 2-3 months and then discarded, or dumped to the owner in csv format.

My objective is to get rid of a dedicated ( and very underused ) instance of splunk and store the logs in the already used FAZ, with the same constraints .

Is someone using a similar configuration, or knows is it possible ?

TIA

 

Arcre

 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!