Hi all,
As far as I know, it is possible to use Chronicle SIEM in multi-tenant environments, and using labels you can "separate" the information for each client. I would like to ask some doubts about this approach:
- Since several clients use the same Chronicle instance, how is the information for each client separated? We understand that it is not a physical separation, but a logical one. Are there any details on this?
- Do you recommend using the "environment" field for this separation of clients or does it have another function?
- Also, since the rules are executed for "all events" matched in the rule, what would be the good practice to delimit/not mix the analysis between clients? Is it done automatically based on some field? Should this logic be added to each rule? We have not seen any documentation on this but we understand that the logic of the rules must contemplate this multi-tenancy, it does not seem to be something internal.
Thanks for your help.
Regards.
M.
