Uly.me

cloud engineer

  • Home
  • About
  • Archives
Home/Archives for tanium

February 24, 2020

Splunk Search for Tanium Clients

Here’s the Splunk search for Tanium clients reporting to the Tanium server.

"data.jsonPayload.rule_details.direction"=EGRESS
"data.jsonPayload.connection.src_ip"="10.0.0.1"
"data.jsonPayload.connection.dest_port"=17472

"data.jsonPayload.rule_details.direction"=EGRESS "data.jsonPayload.connection.src_ip"="10.0.0.1" "data.jsonPayload.connection.dest_port"=17472

  • Cloud
  • Linux
  • Git

Copyright © 2012–2021