To create an extended integration for Tanium user data, you must add session based credentials to Oomnitza.
Best practice is to create a dedicated user account for the credentials that you add to Oomnitza.
To find out how to add credentials for the extended integration for Tanium assets, see Creating an extended integration for Tanium assets.
Before you start
The following information is required to add credential to Oomnitza:
Tanium Domain. The domain name of the Tanium server required to make the request. If your domain is https://my_company_domain/api/v2/api_tokens. You enter my_company_domain/api/v2/api_tokens. That is, you do not include the protocol part https:// of the URL.
Tanium Session String. The session string that is returned when you log in to the Tanium server which is valid for 5 minutes. To retrieve the session string, you can use the Tanium Login or Validate API. For more information, ask your Tanium representative. Alternatively, you can create an API token string in the Tanium Console or you can use the Create Token API. By default, an API token is valid for 7 days. However, you can extend the validity of the token. See See Tanium Console User Guide for Cloud. To learn more, reach out to your Tanium representative.
Adding your Tanium domain as a global variable
The name of the global variable is Tanium.Domain. See Tanium Domain to find out how to enter the domain.
Adding global variables
Save time when you create integrations and run workflows by adding connection information as global variables.
- Click Configuration > General > Global Settings.
- Click Add new variable.
- Add the key value, which is the name of the variable.
- Enter the value.
- Save your changes.
Adding Tanium credentials to Oomnitza
To stream Tanium data into Oomnitza, and the credentials that you obtained to Oomnitza:
- In Oomnitza, click Configuration > Security > Credentials.
- Click Add new credential (+).
- Search for the integration, and then click the forward button > to select the integration.
- Enter your session-based credentials and any other additional information.
- Click CREATE.
Information
If the integration is not listed, click Advanced Mode, and add your credentials.
- Add the information details.
- Click the AUTHORIZATION tab.
- Ensure that Session Based is selected from the Authorization Type list.
- Ensure that Tanium is selected from the SaaS list.
- Click Create.
Ensure you enter the correct Tanium Session String. If you don't, a 401 error, Unauthorized access, is generated.
Comments
0 comments
Please sign in to leave a comment.