Configuring notifications

You can create a connection in Tanium Connect to send a notification when the NAC starts or stops, when an endpoint is quarantined, when a rule match is returned for an endpoint, when a rule is approved or denied, and when rule match violation occurs. You can send these notifications to destinations such as email, SIEM, or Splunk.

Prerequisites

Configure notifications in Connect

  1. Create the connection.
    1. From the Main menu, go to Modules > Connect to open the Connect Overview page. Click Create Connection.
    2. Specify a name and description for the connection.

  2. Configure the data source.
    1. In the Configuration section, select the Event as the Source.
    2. Choose the Network Quarantine event group, then select the events for which you want to generate a notification.
  3. Configure the connection destination.
    Select any of the connection destinations that are listed in the Select Destination menu. Common choices for notifications include Email, SIEM, and Splunk. However, you can use any of the available destinations. For more information, see the Tanium Connect User Guide. Complete the required fields and click Create Connection.