Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-67101 | TANS-SV-000029 | SV-81591r1_rule | Medium |
Description |
---|
While the Tanium Server records audit log entries to the Tanium SQL database, retrieval and aggregation of log data through the Tanium console is not efficient. The Tanium Connect module allows for ArcSight, McAfee SIEM, SIEM, Splunk SIEM, and LogRhythm connectors in order to facilitate forensic data retrieval and aggregation efficiently. |
STIG | Date |
---|---|
Tanium 6.5 Security Technical Implementation Guide | 2016-09-29 |
Check Text ( C-67737r1_chk ) |
---|
Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. Click on "Administration". Select the "Connect" tab. Click on "Configured Connectors". Review for any configured "ArcSight", “McAfee SIEM", "SIEM", "Splunk" or "LogRhythm" connectors. If SIEM connectors are not configured for send log data to offline log collection, this is a finding. |
Fix Text (F-73201r1_fix) |
---|
Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. Click on "Administration". Select the "Connect" tab. Click on "Connector Templates". Choose and configure a template for a SIEM located at the site. |