UCF STIG Viewer Logo

A connector must be configured to send log data to offline log collection.


Overview

Finding ID Version Rule ID IA Controls Severity
V-67101 TANS-SV-000029 SV-81591r1_rule Medium
Description
While the Tanium Server records audit log entries to the Tanium SQL database, retrieval and aggregation of log data through the Tanium console is not efficient. The Tanium Connect module allows for ArcSight, McAfee SIEM, SIEM, Splunk SIEM, and LogRhythm connectors in order to facilitate forensic data retrieval and aggregation efficiently.
STIG Date
Tanium 6.5 Security Technical Implementation Guide 2016-09-29

Details

Check Text ( C-67737r1_chk )
Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC.

Click on "Administration".

Select the "Connect" tab.

Click on "Configured Connectors".

Review for any configured "ArcSight", “McAfee SIEM", "SIEM", "Splunk" or "LogRhythm" connectors.

If SIEM connectors are not configured for send log data to offline log collection, this is a finding.
Fix Text (F-73201r1_fix)
Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC.

Click on "Administration".

Select the "Connect" tab.

Click on "Connector Templates".

Choose and configure a template for a SIEM located at the site.