Service Graph Connector for Tanium
Summarize
Summary of Service Graph Connector for Tanium
The Service Graph Connector for Tanium enables ServiceNow customers to import hardware, software, and software usage data from a Tanium environment directly into their ServiceNow instance. This integration supports enhanced visibility and management of IT assets within the ServiceNow Configuration Management Database (CMDB).
Show less
Supported Versions and Upgrade Considerations
- Supports Tanium versions 1.9+ for hardware and software data, and 1.17+ for software usage data.
- Compatible with ServiceNow releases Washington DC, Xanadu, and Yokohama.
- For Tanium Platform 7.6.2 or later, token-based authorization is mandatory. Customers must reconfigure existing connections from basic to token-based authentication.
- For multiple instances, deactivate old scheduled jobs and create new connections using token authorization.
Configuration
Customers should use the SGC Central view within the Service Graph Workspace or CMDB Workspace to install and configure the connector. This centralized interface allows full lifecycle management of connectors including creation, editing, monitoring, and debugging connections. Note that the older guided setup method is deprecated and should be avoided unless issues arise.
Monitoring and Management
The Integration Commons for CMDB app provides a dashboard that offers a consolidated view of all CMDB integrations, including their status, processing results, and errors. This allows filtering by integration, time period, or specific runs, enabling effective monitoring of Tanium integration health and performance.
Data Mapping and Processing
- Data from Tanium is mapped and transformed into ServiceNow CMDB Configuration Item (CI) classes using the Robust Transform Engine (RTE) and inserted via the Identification and Reconciliation Engine (IRE).
- The connector supports multiple data sources such as applications, hardware, software, software usage, and software removal records, each mapped to corresponding staging and target tables in ServiceNow.
- Software usage data is available only if the Software Asset Management (SAM) Professional plugin is activated.
- Software removal uses a transform map-based approach and includes a configurable buffer period (controlled by the system property
bufferdaysfromlastscanforhardware) to prevent premature deletion based on hardware scan timestamps. - IntegrationHub ETL can be used to view and manage data maps.
Practical Benefits
By integrating Tanium data through this connector, ServiceNow customers gain:
- Comprehensive, accurate hardware and software asset data within their CMDB.
- Enhanced software usage insights when SAM Professional is enabled.
- Automated lifecycle management of asset data including timely removal of outdated software records.
- Centralized integration monitoring and troubleshooting tools to maintain data integrity and operational efficiency.
Use the Service Graph Connector for Tanium to bring in hardware, software, and software usage data from a Tanium environment into your ServiceNow instance.
Request apps on the Store
Visit the ServiceNow Store to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Supported versions
| Tanium | ServiceNow |
|---|---|
|
|
Important information for upgrading Service Graph Connector for Tanium
- For a single instance, reconfigure the authentication type of an existing connection to use token-based authorization.
- For multiple instances, deactivate the existing scheduled jobs for previously configured instances that used basic authorization, and then create and configure new instances to use token-based authorization.
Configuring a connection
CMDB integrations dashboard
The Integration Commons for CMDB store app provides a dashboard with a central view of the status, processing results, and processing errors of all installed integrations. You can see metrics for all integration runs. You can filter the view to a specific CMDB integration, a specific time duration, or a specific integration run. For more details about monitoring Tanium integrations in the CMDB Integrations Dashboard, see Using the CMDB Integrations Dashboard.
Data mapping
Data from the Tanium data sources is mapped and transformed into the ServiceNow CMDB Configuration Item (CI) class definitions using the Robust Transform Engine (RTE). Data is inserted into the ServiceNow CMDB using the Identification and Reconciliation Engine (IRE).
| Data source | Staging table | Target tables | Resource types |
|---|---|---|---|
| SG-Tanium Applications | SG-Tanium Applications [sn_tanium_integ_sg_tanium_applications] |
Running Process TCP |
Applications |
| SG-Tanium Hardware and Software | SG Tanium Import [sn_tanium_integ_sg_tanium_import] |
When the Software Asset Management (SAM) application isn't installed: When the SAM application is installed: |
Server and software |
| SG-Tanium Usage | SG Tanium Usage Import [sn_tanium_integ_sg_tanium_usage_import] |
Software Usage [samp_sw_usage] |
None |
| SG-Tanium Remove Software | Integration Commons Remove Record [sn_cmdb_int_util_remove_record] |
None |
None |
- The SG-Tanium Usage data source is available only when the Software Asset Management Professional plugin (com.snc.samp) plugin is activated on your ServiceNow instance. See Request Software Asset Management.
- The SG-Tanium Remove Software data source creates import sets and uses the transform map-based method for removing any target records for software data that weren't updated in the last delta query check. See Managing CMDB data deletion.
- Starting with the Service Graph Connector for Tanium 1.8.0 release, a buffer time is added for software removal when the buffer_days_from_last_scan_for_hardware system property is enabled. When this system property is enabled, the software removal candidate is removed only if the last scan time of the hardware on which the software removal candidate is installed is earlier than the last success import time + buffer time. To enable this property, set the value of the buffer_days_from_last_scan_for_hardware system property to a non-zero numeral value according to the number of days of buffer that you require. To disable this property, set the value to 0.
You can use the IntegrationHub ETL app to view the data maps. See IntegrationHub ETL for more information.
Additional resource
How do I configure the Tanium Service Graph Connector? article on the ServiceNow Community site