October 29, 2025
TA-Tanium
Field extractions and CIM mappings for Tanium data in Splunk. Normalizes events from Tanium Connect and Tanium Stream so real-time endpoint telemetry, detection signals, inventory, and vulnerability data work with Splunk Enterprise Security and any CIM-based search.Built by Tanium IncSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x
Log in to rate this app
Tanium, an Autonomous IT company, gives IT and security teams complete, accurate endpoint data in real time, at enterprise scale. TA-Tanium is the technology add-on that makes that data usable in Splunk. It parses events sent by Tanium Connect and Tanium Stream, assigns sourcetypes, extracts fields, and maps them to the Splunk Common Information Model (CIM). With the add-on installed, Tanium data populates Splunk Enterprise Security data models (Endpoint, Network Traffic, Authentication, Change, Malware, Vulnerabilities, and others) without custom parsing work. Coverage spans real-time endpoint telemetry (process, network, file, registry, and DNS activity), threat detection signals, asset inventory, vulnerability reports, patch status, and configuration data. Pair this add-on with the Tanium Splunk Application (dashboards) and see the full integration guide in the Tanium Resource Center: https://help.tanium.com/bundle/Integrating-Splunk-with-Tanium
Log in to report this app listing.