Virtual Groups¶
A virtual group is a read-only card, shown alongside your real tenants in the Virtual Tenants grid, that aggregates entities from several tenants into one view. Use it when you want a single pane that spans tenant boundaries — “all of finance across three regions”, or “every high-priority entity regardless of tenant”.
Important
A virtual group is not a tenant. It has no configuration stanza, no roles of its own, no trackers, and no entity ownership. It is not seen by the decision maker and cannot open alerts. It is a visibility layer only. If you need monitoring, ownership, or alerting, create a real tenant instead.
What a group shows¶
The card displays an aggregated entity count and a priority breakdown across all the tenants in scope. A details button opens a group overview. Summaries are always computed live from the underlying tenants’ current state — nothing is cached — so a group is always as fresh as the tenants it aggregates.
Creating a virtual group¶
The creation wizard asks for:
Tenants and components in scope — which tenants, and which of their components, to aggregate.
Optional priority filter — restrict the group to (say) high and critical entities; leave empty for all.
Allowed roles — which Splunk roles may see the group.
Alias and description — the display name and purpose.
Review and create.
You also set a group_id (lowercase, up to 40 characters) and a display
group_alias.
Behaviour and limitations¶
Graceful degradation. Deleted tenants, disabled tenants, and disabled components in scope are silently skipped — the group simply reports fewer entities, never an error.
Empty groups are not auto-hidden. A group whose scope yields nothing shows zero counts; delete it manually if you no longer want it.
Visibility follows roles. A user who belongs to none of the group’s allowed roles simply does not see it.
No SLA rollup and no group-level acknowledgment today — entities are still acknowledged in their own tenant.
See also
Virtual Tenants explained — real tenants, which groups aggregate.
Classification & Protection — the priority levels used by the group filter.