Skip to main content
Has your work email already leaked?Run the 10-second check
SIEM for MSPs

One SIEM is a project. Forty is a business model.

The hard part of running a SIEM for clients is not the SIEM. It is tenant isolation you can evidence, data cost you can attribute, and an onboarding that is a procedure by the fifth client rather than a project every time.

What this is

A multi-tenant SIEM for MSPs and MSSPs: one platform carrying many client environments, with data, detections and reporting separated per tenant, operated by Vijilan's 24/7 SOC and delivered under the partner's brand.

ThreatLog™, an index-free SIEM, ships in every ThreatRespond™ tier rather than arriving as a separate purchase per client. Where a client wants CrowdStrike Falcon® Next-Gen SIEM in their own name, NextDefend™ covers that instead.

Index-free retention is the structural point for a channel business: per-gigabyte ingestion pricing means every improvement in a client's coverage increases your bill, which quietly pays you to collect less than you should.

The multi-tenant problem

Four things that only break at scale.

None of these matter with one client. All of them decide whether the practice is profitable with forty.

Isolation that survives an audit

One client must never see another’s data, and you must be able to show that rather than assert it. Tenancy that is a dashboard filter rather than a boundary is the thing that ends a contract when it is discovered.

Cost attributable to the client who caused it

Per-gigabyte ingestion across a shared platform becomes unmanageable the moment one client onboards a chatty firewall. Index-free retention removes most of that problem; the rest is knowing whose data it is before the invoice, not after.

Onboarding that repeats

The first tenant is a project. The fortieth has to be a procedure, with the connectors, parsers and detection baseline reused rather than rebuilt. Margin in this business is made or lost on that difference.

Detection tuned per client, maintained centrally

Clients differ enough that shared detection logic produces noise, and differ little enough that maintaining forty separate rule sets is impossible. The workable answer is a common baseline with per-tenant overrides, and somebody whose job is keeping it current.

Questions

Asked by people who already run one.

What is a multi-tenant SIEM?

A SIEM architected so one operator can run many customers on it with their data, detections and reporting genuinely separated. The word is used loosely: some platforms achieve separation with access controls over a shared index, which is not the same as isolation and does not survive scrutiny in a client security review.

Do we have to buy a SIEM per client?

No, and that is usually the point of the arrangement. The SIEM comes with the service rather than as a separate purchase per tenant. ThreatLog™, index-free, is included in every ThreatRespond™ tier, and NextDefend™ is available where a client wants CrowdStrike Falcon® Next-Gen SIEM in their own name.

What does the data cost as we grow?

Rates are channel rates and sit behind partner verification, but the structure matters more than the number and is worth understanding first. Per-gigabyte ingestion pricing means every improvement in a client’s coverage raises your bill, which quietly rewards you for collecting less. Index-free retention breaks that link. The cost drivers are set out in full on the SOC cost page.

Can we white-label it?

Yes. Your brand on the console, the reports and the client communications, and we never compete with our partners for their clients. That is a promise about our conduct rather than a restriction on who can buy from us.

What happens to a client who leaves us?

Their data is theirs. Ask any provider this before signing rather than during an exit, because the answer determines whether an unhappy client becomes a difficult conversation or an impossible one.

We already run a SIEM for our clients. Can you operate it?

Often, yes. ThreatRespond™ is vendor-agnostic and wraps the SOC around tooling you already own. Where the existing platform is the problem rather than the staffing, the migration program covers moving off Splunk, QRadar, Sumo Logic, Rapid7, Elastic, ArcSight, LogRhythm and Exabeam without a coverage gap.

Who does the parser work?

We do, and it is worth asking because it is the part that consumes engineering time nobody budgeted. Sources with a purpose-built connector are quick. The ones without are where SIEM projects lose their schedule, and they are the reason a per-tenant onboarding procedure is worth more than a per-tenant license.

We're online · book a SOC walkthrough today

Bring us your messiest
client environment.

The useful conversation is about the tenant that is hard to onboard, not the one that is easy. Tell us about that one and we will be specific about what it takes.