All Apps and Add-ons

How to Integrate Tanium with Splunk Cloud..?

harishalipaka
Motivator

Hi All,

I'm about to integrate Tanium Connect with Splunk Cloud ( Not Splunk Enterprise ) to forward data from Tanium to Splunk Cloud in the 'syslog' format.

In this regard, I would like to know details on the following -

  1. Connection settings that need to be done in Tanium Connect ( like what to be filled in port no ,host name etc ) ,
  2. Is there any difference in forwarding data from Tanium Connect to Splunk Enterprise and Splunk Cloud OR is it same for both,
  3. what are the list of ports that need to be opened in them system where Tanium console is installed,
  4. Which port is used for communication between Tanium connect and Splunk cloud,
  5. Any URL that need to be white-listed in the Firewall that is present in the network where, Tanium is present,
  6. what are the methods that are implemented in Splunk cloud to secure data,
  7. What are the security measures that are followed while sending data from Tanium to Splunk cloud etc.,

ThanQ in advance 🙂

Thanks
Harish
0 Karma

mydog8it
Builder

Tanium only provides output to syslog and SplunkCloud does not have a syslog collector available in the cloud. So, the solution I deployed was to collect the data on-premise in a syslog server with a UF installed. Create an config for the UF to watch the file system the syslog server writes to and the data will be forwarded out the same way that any of your on-prem data flows to SplunkCloud. No additional firewall rules unless you need one to get from the Tanium server to the syslog server.

0 Karma

amiracle
Splunk Employee
Splunk Employee

When sending data into Splunk Cloud, you'll need to forward the data in using a UF or HF (depending on your app). In this case, it seems like Tanium will send data to a syslog server and then you can forward it from there into Splunk Cloud using the forwarder app on your cloud stack.

I'm not too familiar with the Tanium Connect piece For Splunk, you might want to reach out to Tanium directly about that setting. You can also hit them up on the splunk-usergroups.slack.com on the #tanium channel.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...