Tanium File Integrity Monitoring for ServiceNow offers the following core functionalities:
- Captures Tanium IM Events from specified Integrity Monitor watchlists.
- Stores Event details in ServiceNow for Event Managers to review.
- Checks for existing Change Request tickets associated with the CI, including the event's time within the change window.
- Optionally disregards the event as an 'authorized change' if a related Change Request is found (configurable).
- Creates a 'Tanium IM Alert' record if no related Change Request is found or if configured to ignore Changes for that watchlist. This record can generate a ticket in a chosen table with configurable, pre-filled dynamic field values at the Watchlist level.
Tanium IM (Integrity Monitor) and Unauthorized Change Monitoring application for ServiceNow.
The “Tanium File Integrity and Unauthorized Change Monitoring” application has the following core functionality and behavior:
1. Takes Tanium IM Events from certain Integrity Monitor watchlists that you specify,
2. Stores those Event details in ServiceNow, where Event Managers can review the details of each Event.
3. Detects whether there's an existing Change Request ticket associated with the CI, which has a change window that includes the time that the event happens.
4. If so, optionally disregards the event (which you can configure) as an "authorized change"
5. If a related Change is not found (or if configured to ignore Changes for that watchlist), it creates a "Tanium IM Alert" record which can generate a ticket in a table of your choice, with pre-filled dynamic field values that you can configure at the Watchlist level.