All Apps and Add-ons

How to Integrate Tanium with Splunk Cloud..?

harishalipaka
Motivator

Hi All,

I'm about to integrate Tanium Connect with Splunk Cloud ( Not Splunk Enterprise ) to forward data from Tanium to Splunk Cloud in the 'syslog' format.

In this regard, I would like to know details on the following -

  1. Connection settings that need to be done in Tanium Connect ( like what to be filled in port no ,host name etc ) ,
  2. Is there any difference in forwarding data from Tanium Connect to Splunk Enterprise and Splunk Cloud OR is it same for both,
  3. what are the list of ports that need to be opened in them system where Tanium console is installed,
  4. Which port is used for communication between Tanium connect and Splunk cloud,
  5. Any URL that need to be white-listed in the Firewall that is present in the network where, Tanium is present,
  6. what are the methods that are implemented in Splunk cloud to secure data,
  7. What are the security measures that are followed while sending data from Tanium to Splunk cloud etc.,

ThanQ in advance 🙂

Thanks
Harish
0 Karma

mydog8it
Builder

Tanium only provides output to syslog and SplunkCloud does not have a syslog collector available in the cloud. So, the solution I deployed was to collect the data on-premise in a syslog server with a UF installed. Create an config for the UF to watch the file system the syslog server writes to and the data will be forwarded out the same way that any of your on-prem data flows to SplunkCloud. No additional firewall rules unless you need one to get from the Tanium server to the syslog server.

0 Karma

amiracle
Splunk Employee
Splunk Employee

When sending data into Splunk Cloud, you'll need to forward the data in using a UF or HF (depending on your app). In this case, it seems like Tanium will send data to a syslog server and then you can forward it from there into Splunk Cloud using the forwarder app on your cloud stack.

I'm not too familiar with the Tanium Connect piece For Splunk, you might want to reach out to Tanium directly about that setting. You can also hit them up on the splunk-usergroups.slack.com on the #tanium channel.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...