With Discover, you can find and maintain an inventory of interfaces in your environment. By installing the Tanium™ Client on your endpoints, you can actively monitor the local subnet, detect unmanaged interfaces, and report the interfaces to Discover. You can then perform the following tasks:
- Deploy Tanium Client to bring endpoints under management.
- Get real-time information about unmanaged interfaces on your network.
- Block unmanaged interfaces from network access.
Tanium-managed endpoints scan for or detect unmanaged interfaces at configurable intervals. Discover queries endpoints for updated detection data periodically. New information is immediately available. The detection process provides continuous scanning without impact to network operations.
Discover is integrated with a collection of sensors, packages, and actions. With this tool set, you can bring network interfaces under management within minutes of detection.
You can choose between several discovery methods that detect interfaces that are on the network but not under Tanium management. Tanium Client initiates scans at regular intervals throughout the network environment. For more information, see Discovering unmanaged interfaces.
You can use the Discover Client Deploy solution to deploy the Tanium Client to the unmanaged interfaces to bring the computers under management by Tanium™ Server. For more information, see Deploying Tanium Client to unmanaged endpoints.
Labels include descriptive information or metadata that you can use to identify and group interfaces. Then, you can classify or search interfaces based on the labels. You can also automatically apply labels or ignore interfaces based on a specifically defined set of conditions. For more information about labels, see Managing interfaces .
Discover integrates with NAC solutions that perform network access blocking. With this capability, you can quickly identify and block rogue interfaces from the network.
Tanium™ Network Quarantine
Use the Network Quarantine shared service to set up a NAC that can block by IP or MAC address.
For more information, see Block network access with Network Quarantine.
Configure blocking and unblocking connections with Palo Alto Networks NG Firewall to provide network access control blocking as a built-in action of Discover.
For more information, see Block network access with Connect.
Discover records events when an unmanaged interface is found, a new managed endpoint is found, or if an interface is lost. Discover can send these events to another system, such as a SIEM, email, or file, with a connection in Connect. This connection sends the event notification from Discover to a configured destination. For more information about configuring the Discover notifications connection, see Configuring Discover notifications.
This documentation may provide access to or information about content, products (including hardware and software), and services provided by third parties (“Third Party Items”). With respect to such Third Party Items, Tanium Inc. and its affiliates (i) are not responsible for such items, and expressly disclaim all warranties and liability of any kind related to such Third Party Items and (ii) will not be responsible for any loss, costs, or damages incurred due to your access to or use of such Third Party Items unless expressly set forth otherwise in an applicable agreement between you and Tanium.
Further, this documentation does not require or contemplate the use of or combination with Tanium products with any particular Third Party Items and neither Tanium nor its affiliates shall have any responsibility for any infringement of intellectual property rights caused by any such combination. You, and not Tanium, are responsible for determining that any combination of Third Party Items with Tanium products is appropriate and will not cause infringement of any third party intellectual property rights.
Last updated: 1/15/2019 1:44 PM | Feedback