Skip to main content
TA-Tanium app icon

TA-Tanium

Field extractions and CIM mappings for Tanium data in Splunk. Normalizes events from Tanium Connect and Tanium Stream so real-time endpoint telemetry, detection signals, inventory, and vulnerability data work with Splunk Enterprise Security and any CIM-based search.Built by Tanium Inc
splunk product badge

Default Version 1.7.5

October 29, 2025

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x

Rating
4
(3)

Log in to rate this app

Support
Developer Supported

Tanium, an Autonomous IT company, gives IT and security teams complete, accurate endpoint data in real time, at enterprise scale. TA-Tanium is the technology add-on that makes that data usable in Splunk. It parses events sent by Tanium Connect and Tanium Stream, assigns sourcetypes, extracts fields, and maps them to the Splunk Common Information Model (CIM). With the add-on installed, Tanium data populates Splunk Enterprise Security data models (Endpoint, Network Traffic, Authentication, Change, Malware, Vulnerabilities, and others) without custom parsing work. Coverage spans real-time endpoint telemetry (process, network, file, registry, and DNS activity), threat detection signals, asset inventory, vulnerability reports, patch status, and configuration data. Pair this add-on with the Tanium Splunk Application (dashboards) and see the full integration guide in the Tanium Resource Center: https://help.tanium.com/bundle/Integrating-Splunk-with-Tanium