Skip to main content
Tanium Splunk Application app icon

Tanium Splunk Application

Prebuilt dashboards for Tanium data in Splunk: endpoint operations, asset inventory, discovery, patch posture, compliance, integrity monitoring, and threat response. Requires the TA-Tanium add-on for parsing and CIM mapping.Built by Tanium Inc
splunk product badge

Default Version 7.8.2

October 29, 2025

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x

Rating
5
(10)

Log in to rate this app

Support
Developer Supported

Tanium, an Autonomous IT company, gives IT and security teams complete, accurate endpoint data in real time, at enterprise scale. The Tanium Splunk Application puts that data to work with prebuilt dashboards for both IT operations and security teams. Operations views cover endpoint management health, application visibility, asset inventory, user-to-endpoint mapping, and unmanaged device discovery. Security views cover threat response, patch posture, compliance findings, integrity monitoring, data leakage indicators, and network connection detail. Data arrives through Tanium Connect and Tanium Stream. This app requires the Tanium Technology Add-on (TA-Tanium), which handles parsing, field extraction, and CIM mapping: https://splunkbase.splunk.com/app/4439 Full integration guide in the Tanium Resource Center: https://help.tanium.com/bundle/Integrating-Splunk-with-Tanium The Tanium Splunk Application contains a set of dashboards that correspond to a fixed set of Tanium questions and sources that populate the data. The dashboards display data across operations and security and allow deep endpoint insights and context.