All Apps and Add-ons

Tanium app inputs

ccsfdave
Builder

I have a bunch of inputs that the tanium SME wants pulled into Splunk. I can’t find documentation on the app and whether it is looking for different sourcetypes etc. Is there a best practice on organizing the data coming in?
example:

Tanium App/DB Appliance: (update)
Tanium Module Appliance: (tanmod)
Tanium Deploy Fileserver (tanfile)
Tanium DMZ Appliance (tanzonea)

BTW if anyone comments, the above is coming into a HWF via UDP 514. We also have a HEC 8002 for other Tanium data coming in

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...