You can create a connection in Tanium Connect to send a notification when the NAC starts or stops, or when an endpoint is quarantined. You can send these notifications to destinations such as email, SIEM, or Splunk.
- Create the connection.
- From the Main menu, open Connect. Click Create Connection.
- Name the connection.
In General Information, confirm that Enable is selected.
- Configure the data source.
- (Optional) Filter the data.
You can optionally filter for new items, regular expressions, numeric operators, or unique values from data columns.
- Configure the connection destination.
Select any of the connection destinations that are listed in the Select Destination menu. Common choices for notifications include Email, SIEM, and Splunk. However, you can use any of the available destinations. For more information, see the Tanium Connect User Guide. Complete the required fields and click Create Connection.
Last updated: 10/19/2018 2:08 PM | Feedback