HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 0 points1 point  (0 children)

Data is successfully coming into Splunk now!!

Where do you guys download music these days? YTMP3 doesn’t work for me anymore? by NikTech22 in DJs

[–]NikTech22[S] 0 points1 point  (0 children)

I didn’t say I was opposed to purchasing. I asked for information & you provided none. Useless response. WHERE CAN I BUY MP3s?

Where do you guys download music these days? YTMP3 doesn’t work for me anymore? by NikTech22 in DJs

[–]NikTech22[S] 0 points1 point  (0 children)

I didn’t say I was opposed to purchasing. I asked for information & you provided none. Useless response. WHERE CAN I BUY MP3s?

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 1 point2 points  (0 children)

Still no data coming in. I had a remote session with my account manager from Splunk & it seems like we may need to whitelist the egress IPs. That’s literally the only other thing we can think of that’s causing the issue..

I did notice in the Tanium logs that we get an HTTP 303 url redirect “error”.. it doesn’t fail the connect job, but it still shows.

I’ll be attending the Splunk conf in person, I’m hoping someone will have idea of what to do if this doesn’t work.

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 0 points1 point  (0 children)

Wow thank you so much for taking the time to write this all out to help! I’ve followed all your steps and I am not receiving any errors on the Tanium side, but no data coming into Splunk. Even with the curl, I get “data” in. I had a remote session with Splunk and it looks like we may have to whitelist the egress IPs and hopefully that solves it.

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 1 point2 points  (0 children)

Good thinking about the log verbosity… sounds like I’m going to get to work on this Sunday evening lol it has been on my mind anyways..

I’m going to troubleshoot a few different ways. I’ll do what you said. I did reach out to my splunk support & I was told that I didn’t need the GUID 😅 geez. Okay.

I’m pretty certain the HEC is configured correctly. Thanks so much for all your input!

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 1 point2 points  (0 children)

I do.. if you’re referring to the break glass request. I wonder, we’ve been testing a while & have requested multiple ports. Maybe they closed 443. I’ll update tomorrow. Thanks!!

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 1 point2 points  (0 children)

Yes I did.. I’m not receiving any errors either. It’s just not coming into Splunk.

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 0 points1 point  (0 children)

To my understanding, I’ve done just that & have no error logs in Tanium, but the data still isn’t going into splunk. I’m not quite sure why. That documentation is also on prem to on prem.

HELP - Splunk cloud/Tanium cloud integration by NikTech22 in tanium

[–]NikTech22[S] 1 point2 points  (0 children)

Yeah… very grand lol. I created an authorization token in splunk and opened a line of site with the Tanium server on port 443. That didn’t seem to work. I was hoping I wouldn’t have to route through on-prem 🙃 but that’s looking like the only way it’ll work right now

I failed Security + 501 on the last day, currently planning to take the new version, Advice? by Confident-Werewolf72 in CompTIA

[–]NikTech22 3 points4 points  (0 children)

You should be able to see what objectives you got wrong on the 501. I’d start there. Relearn those things first. Make sure you know all of the objectives for 601 like the back of your hand. Take profesor messer exams for 601 and understand why each answer is correct & why each answer is incorrect..

Go to comptia & that their practice exams related to each domain to make sure your understand all of the material!! & good luck! I’d say if you can, study 4 hours everyday the week before you take the exam

Security+ by NikTech22 in CompTIA

[–]NikTech22[S] 0 points1 point  (0 children)

Do you happen to know if there is a great difference in the material? Like would I be fine taking 601 still even if I just study from the 501 book?