SV-253844r997268_rule
V-253844
SRG-APP-000115
TANS-SV-000010
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web UI and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Expand the left menu.
5. Click "Connections".
6. Click "Create Connection" or if importing, click "Import".
7. Give the "Connection" a name and description.
8. In the "Configuration" section, select "Event" as the source.
9. Select appropriate source under "Event Group" - any source to generate interest-based events (Discover, Asset, IM, THR, etc).
10. Select the appropriate events to send.
Note: Consult with the Tanium system administrator for the Destination.
11. Select "Listen for this Event".
12. Click "Save".
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Click "Connections" under "Connections" section.
5. Filter by source and review event-based sources.
If any event=based sources have a failed run for more than 72 hours, this is a finding.
V-253844
False
TANS-SV-000010
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Click "Connections" under "Connections" section.
5. Filter by source and review event-based sources.
If any event=based sources have a failed run for more than 72 hours, this is a finding.
M
5476