Child tenant management

You can manage, track, and investigate child tenant data from the parent tenant.

Manage a child tenant in Cortex XSIAM

Multi-tenancy enables you to view and investigate Cortex XSIAM data of a child tenant and initiate security actions on their behalf.

In Cortex XSIAM, you have access to view the following pages:

  • Cases
  • Issues
  • Query Builder
  • Query Center and Results
  • Causality View
  • Timeline View

To initiate security actions on your child tenant, you need to create a Configuration. Security actions are managed by configurations you create in Cortex XSIAM and then assign to each of the child tenants. Each action requires its own configuration and allocation to a child tenant.

Once a configuration is created, Cortex XSIAM resets the child tenant data and synchronizes the security actions configured in the parent tenant.

You can create configurations for the following actions:

  • Starred Issue Policies
  • Issue Exclusions
  • Profiles
  • Allow/Block Lists