• Skip to main content

Uly.me

cloud engineer

  • Home
  • About
  • Archives

splunk

Splunk Search for Tanium Clients

February 24, 2020

Here’s the Splunk search for Tanium clients reporting to the Tanium server.

"data.jsonPayload.rule_details.direction"=EGRESS
"data.jsonPayload.connection.src_ip"="10.0.0.1"
"data.jsonPayload.connection.dest_port"=17472

"data.jsonPayload.rule_details.direction"=EGRESS "data.jsonPayload.connection.src_ip"="10.0.0.1" "data.jsonPayload.connection.dest_port"=17472

Filed Under: Misc Tagged With: 17472, port, splunk, tanium

  • Home
  • About
  • Archives

Copyright © 2023