Reference: Index sensors

Use the Index sensors to get details about files that have been indexed.

Sensor Description
Index - File Count Returns count of index files that match one or more supplied inputs. The Index - File Count sensor supports both wildcards and regular expressions. Supported wildcard syntax includes the character to match any number of characters and the ? character to match one character. For example, you can use pad.exe to search for either notepad.exe or wordpad.exe. To use regular expressions in parameter values, select Use Regular Expressions. You can use regular expressions to search for more complex patterns and to further constrain the scope of the search. For example, ^(if|ip)config(.exe)?$ matches ifconfig, ipconfig, ifconfig.exe, and ipconfig.exe.
Index - File Details Returns details of index files that match one or more supplied inputs. The Index -File Details sensor supports both wildcards and regular expressions in parameters with the exception of the Maximum Number of Rows. Supported wildcard syntax includes the character to match any number of characters and the ? character to match one character. For example, you can use pad.exe to search for either notepad.exe or wordpad.exe. To use regular expressions in parameter values, select Use Regular Expressions. You can use regular expressions to search for more complex patterns and to further constrain the scope of the search. For example, ^(if|ip)config(.exe)?$ matches ifconfig, ipconfig, ifconfig.exe, and ipconfig.exe.
Index - File Exists Returns Yes or No, using Index to determine whether specified file exists based on the supplied input. The Index - File Exists sensor uses Tanium Index to determine whether the specified file(s) exist on the endpoints and returns "Yes" or "No". The Index - File Exists sensor supports both wildcards and regular expressions. Supported wildcard syntax includes the character to match any number of characters and the ? character to match one character. For example, you can use pad.exe to search for either notepad.exe or wordpad.exe. To use regular expressions in parameter values, select Use Regular Expressions. You can use regular expressions to search for more complex patterns and to further constrain the scope of the search. For example, ^(if|ip)config(.exe)?$ matches ifconfig, ipconfig, ifconfig.exe, and ipconfig.exe.
Index - File Hash Recently Changed Returns filename and hash(es) of file created or modified in previous N hours. The Index - File Hash Recently Changed sensor returns filenames and hashes for files that have been created or modified within a given number of hours. For example, you can search for binary files that have been created or modified under C:\WindowsSystem32 in the previous 8 hours. By searching for files with a File Magic Number glob of 4D5A, you can focus your search on Windows PE binary files (EXEs and DLLs). The Index - File Hash Recently Changed sensor supports both wildcards and regular expressions in parameters with the exception of the Maximum Number of Rows and Lookback Hours parameters. Supported wildcard syntax includes the character to match any number of characters and the ? character to match one character. For example, you can use pad.exe to search for either notepad.exe or wordpad.exe. To use regular expressions select Use Regular Expressions. You can use regular expressions to search for more complex patterns and to further constrain the scope of the search. For example, ^(if|ip)config(.exe)?$ matches ifconfig, ipconfig, ifconfig.exe, and ipconfig.exe.

There is no longer an Index DB Size Sensor for Index. Use the Sensor "File Size" from default content.
Get File Size["c:\Program Files (x86)\Tanium\Tanium Client\extensions\index\index.db"] from all machines

The following Index sensors have been deprecated:

  • Index Has Latest Tools
  • Index Query File Count
  • Index Query File Details
  • Index Query File Details by Last Modified
  • Index Query File Details Using Name
  • Index Query File Details Using Name Sort By Largest
  • Index Query File Exists
  • Index Query File Hash Recently Changed
  • Index Query File Path and Hash
  • Index Query File Path Using Name
  • Index Query File Permissions
  • Index Query Find Blacklist Matches
  • Index Resolved Config
  • Index Status
  • Index Version