Actions for Tanium Discover #
- Send Data to Tanium Discover. Sends a custom set of Lucidum data to Tanium Discover.
Use Cases #
Below are the possible use cases for these actions:
-
If you want to run Lucidum “headless”, you can send relevant data to Tanium Discover on a regular schedule.
- You can send normalized, enriched Lucidum data to Tanium Discover to be indexed, searched, and analyzed.
Prerequisites #
To execute Tanium Discover actions, you must:
- Configure a Tanium Discover API connection beforehand. The required parameters are described in the instructions for creating a Tanium Discover connector in Lucidum https://lucidum.io/docs/tanium-discover/.
NOTE. The specified account should have read and write permissions.
Workflows #
- Creating a new Configuration and a new Action
- Cloning an Existing Action
- Creating a new Action from the Location Results page
- Editing a Configuration
- Editing an Action
- Viewing Information about an Action
Tanium Discover Configuration #
To create a configuration for Tanium Discover actions:
-
Configuration Name. Identifier for the Configuration. This name will appear in the Lucidum Action Center.
-
URL. The URL for the Tanium Discover API. For example, https://tanium_discover/api/v2/.
-
Username. User name for a Tanium Discover account with read and write access to the API.
-
Password. Password for a Tanium Discover account with read and write access to the API.
-
Domain. Domain for Tanium Discover
-
API Token. If you are connecting to a Tanium cloud instance, you must provide an API token. The API token should be for an account that has read and write access to the Tanium Discover APIs. For details, see https://help.tanium.com/bundle/ug_console_cloud/page/platform_user/console_api_tokens.html.
- Proxy. If you are using a proxy server to allow this connector to communicate with on-premises devices, enter the IP address: port for the proxy server, usually 192.168.255.6:3128.
-
Max # of Records per Payload. The maximum number of records to send to Tanium Discover in each action. The default value is “50”.
Create a New Action #
To create an action for Tanium Discover, contact Lucidum customer care.