Tanium, an Autonomous IT company, gives IT and security teams complete, accurate endpoint data in real time, at enterprise scale.
The Tanium Splunk Application puts that data to work with prebuilt dashboards for both IT operations and security teams. Operations views cover endpoint management health, application visibility, asset inventory, user-to-endpoint mapping, and unmanaged device discovery. Security views cover threat response, patch posture, compliance findings, integrity monitoring, data leakage indicators, and network connection detail.
Data arrives through Tanium Connect and Tanium Stream. This app requires the Tanium Technology Add-on (TA-Tanium), which handles parsing, field extraction, and CIM mapping: https://splunkbase.splunk.com/app/4439
Full integration guide in the Tanium Resource Center: https://help.tanium.com/bundle/Integrating-Splunk-with-Tanium
The Tanium Splunk Application contains a set of dashboards that correspond to a fixed set of Tanium questions and sources that populate the data. The dashboards display data across operations and security and allow deep endpoint insights and context.