I installed Splunk Tanium app in my environment, Can you please help me for the configuration in Splunk for tanium
In which configuration file i need to edit and get the data in SPlunk for tanium
Step 1:
Step 2:
monitor tanium logs from syslog server
inputs.conf on HF: Example
[monitor:///syslog/tanium//.log]
disabled = 0
followTail = 0
host =
host_segment = 3
index = main
sourcetype = tanium
crcSalt =
props.conf exaple on HF
[tanium]
KV_MODE = json
MAX_TIMESTAMP_LOOKAHEAD = 16
NO_BINARY_CHECK = true
SEDCMD-strip_prefix = s/^[^{]+//g
SHOULD_LINEMERGE = false
TIME_FORMAT = %b %d %H:%M:%S
TIME_PREFIX = ^
category = Custom
disabled = false
pulldown_type = true
Hope this helps...
Step 1:
Step 2:
monitor tanium logs from syslog server
inputs.conf on HF: Example
[monitor:///syslog/tanium//.log]
disabled = 0
followTail = 0
host =
host_segment = 3
index = main
sourcetype = tanium
crcSalt =
props.conf exaple on HF
[tanium]
KV_MODE = json
MAX_TIMESTAMP_LOOKAHEAD = 16
NO_BINARY_CHECK = true
SEDCMD-strip_prefix = s/^[^{]+//g
SHOULD_LINEMERGE = false
TIME_FORMAT = %b %d %H:%M:%S
TIME_PREFIX = ^
category = Custom
disabled = false
pulldown_type = true
Hope this helps...
Thanks it really helps me 🙂