You use Tanium Interact to issue questions to managed endpoints, analyze their answers, and deploy actions to the endpoints based on the answers. Although it is licensed as part of the Tanium Core Platform, Interact is a Tanium module, so you can update it separately from the Tanium Console and the Tanium Server.
A Tanium question is a query that you issue from the Tanium Server to managed endpoints. A dynamic question is one that you create and issue through the Ask a Question or Question Builder features in Interact. A saved question is a configuration object that enables you to reissue a question without reconstructing it through those features.
The Ask a Question feature is built on a natural language parser that enables you to get started with natural questions rather than a specialized query language. You do not need to enter questions as complete sentences or particularly well-formed inquiries. Word forms are not case sensitive and can even include misspellings. The parser interprets your input and suggests a number of valid queries that you can use to formalize the question that is sent to Tanium Clients. Interact provides the Ask a Question feature as a text-entry field in the Question Bar at the top of the Interact Home page and Interact Content page.
The following figure shows an example of how natural language input is parsed into proposed queries. First, the user enters the fragment last logged in user and clicks Search. In response, Interact returns a list of queries cast in valid syntax.
Questions have a get clause that specifies the information to retrieve and a from clause that specifies the target endpoints. Basic questions include the following:
- One or more sensor names (such as Last Logged In User) in the get clause
- From all machines (all endpoints that host the Tanium Client) in the from clause
Advanced questions include filter clauses and parameterized sensors.
For the steps to issue questions and view question history, see Asking questions . For more information about question syntax, see Reference: Example questions and Reference: Advanced question syntax.
A sensor is a script that runs on an endpoint to compute a response to a Tanium question. The Tanium Server distributes sensors to endpoints during Tanium Client registration. Sensors enable you to ask questions that collect information such as the following:
- Hardware and software inventory and configuration
- Running applications and processes
- Files and directories
- Network connections
The installation process for the Tanium Server automatically imports Initial Content packs that include sensors for a wide range of common questions. Other Tanium solutions that you import might add more sensors, depending on which Tanium content packs or Tanium solution modules you import. If you cannot find a sensor you need within Tanium-provided content, you can create custom sensors.
For more information, see Tanium Console User Guide: Managing sensors.
A counting question is one that returns results in which it is possible for any particular answer string to be the same for multiple endpoints. The Question Results grid displays a Count column that indicates how many endpoints provided each common answer. A counting question can have only one sensor. Get Tanium Client Logging Level from all machines is an example of a counting question, with a sensor that returns the value of the LogVerbosityLevel setting. When an endpoint is prompted to add its answer to the answer message, it increments the tally of the answer that its value matches. The Tanium Server maintains a table of answer strings. In many cases, such as the logging level, many endpoints provide just a few common answers, so the question has a relatively small footprint on the Tanium Server.
A non-counting question has sensors that return a unique answer string from each endpoint. For example, Get Tanium Client IP Address from all machines returns IP addresses, which are unique. When a Tanium Client is prompted to add its answer to the answer message, it adds a new string. On the Tanium Server, the data footprint for a non-counting question can be large.
When using the Question Builder to construct a question, you have the option to convert a counting question to a non-counting question for cases where a counting question returns the too many results answer.
When you construct a question, use the AND operator in the get clause to specify multiple sensors. The Question Results page groups results by the first sensor, then by the next sensor, and so on, as the following example illustrates.
A parameterized sensor uses a value that you specify when entering the question in the Question Bar or Question Builder. The following example shows the File Exists sensor. The Tanium Console prompts you to specify a file path and file name.
Another example is the High CPU Processes sensor. You can specify a parameter that is the number of CPU processes to return from each machine. For example, you might want to get the top 5 highest CPU utilizing processes. The question has the following syntax:
Get High CPU Process from all machines
For sensors with multiple parameters, you can specify an ordered list of comma-separated parameters. For example, to see the first 10 lines from the action log for the action with ID 1, specify a parameter list as follows:
Get Tanium Action Log[1,10] from all machines
You can use filters to create questions that target fewer endpoints than the default all machines. For example, the following advanced question targets only endpoints that have a specific process name or value.
The left side (get clause) is a complete and valid query; the right side contains a filter: the from all machines with expression. Filters in the from clause are the first part of a question that an endpoint processes. If the endpoint data does not match the filter, the endpoint does not process the question any further. If the question has multiple filters, the endpoint evaluates each filter. The filter expression must evaluate to a Boolean true or false. For example, the expression with Running Processes contains explore evaluates to true if the specified string matches the result string, or false if it does not. If a filter evaluates to true, the endpoint runs the sensors on the left side of the question and returns the results.
A parameterized sensor like File Exists returns the string File Exists: Filename or File does not exist, so be careful how you enter the sensor in a filter expression.
The filter expression with File Exists["C:\Program Files\PuTTY\putty.exe"] containing "Exists" evaluates to true when the result is File Exists: C:\Program Files\PuTTY\putty.exe and false when the result is File does not exist, so you can use it to filter the set of responses.
Filter expressions can match strings or regular expressions. The following table describes the supported filter operators as they appear when you use the Question Builder. The table also describes how some operators are normalized after you load them from the Question Builder or enter the expressions in the Question Bar.
Sensor value contains the specified string.
Example: running processes contains "explore"
|does not contain||Sensor value does not contain the specified string.|
|starts with||Sensor value starts with the specified string.
Example: starts with "explore"
|does not start with||Sensor value does not start with the specified string.|
Sensor value ends with the specified string.
Example: ends with "explore.exe"
|does not end with||Sensor value does not end with the specified string.|
|matches||Sensor value matches the specified regular expression (in Boost syntax).|
|does not match||Sensor value does not match the specified regular expression.|
|in||Sensor value matches one of the specified strings. Use commas without spaces to separate the strings. When you load the question, the expression shown in the question bar uses equals and or operators in place of in.
Example: The filter in "10.10.10.10,10.10.10.11" in the Question Builder becomes IP Address equals 10.10.10.10 or IP Address equals 10.10.10.11 when you load the question.
|is equal to||Sensor value is equal to the specified value or string. When you load the question, the expression shown in the question bar uses equals in place of is equal to.|
|is not equal to||Sensor value is not equal to the specified value or string. When you load the question, the expression shown in the question bar uses not equals in place of is not equal to.|
|is less than||
Sensor value is less than the specified value. When you load the question, the expression shown in the question bar uses a symbol (<) in place of the operator words.
Example: installed application version[chrome] < 12
|is less than or equal to||
Sensor value is less than or equal to the specified string.
When you load the question, the expression shown in the question bar uses symbols (<=) in place of the operator words.
Example: installed application version[chrome] <= 12
|is greater than||
Sensor value is greater than the specified value.
When you load the question, the expression shown in the question bar uses a symbol (>) in place of the operator words.
Example: installed application version[chrome] > 12
|is greater than or equal to||
Sensor value is greater than or equal to the specified string. When you load the question, the expression shown in the question bar uses symbols (>=) in place of the operator words.
Example: installed application version[chrome] >= 12
See Reference: Advanced question syntax for examples of complex filter expressions, including questions with multi-column sensors.
Upon issuing a dynamic or saved question, the Tanium Server assigns a question ID to the question. The question ID appears in the URL field of your web browser. After 10 minutes, the question ID expires and its URL becomes invalid. This means you can refresh the page or share the link only within that 10-minute period.
If you navigate to the URL after 10 minutes, Interact displays a Question Expired message and provides the option to copy the question text to the Question Bar so that you can reissue it.
Saved questions are questions that you can reissue without reconstructing them in the Interact Question Bar. They are configuration objects for which you can define reissue intervals, access permissions, associated actions, and other settings. You can issue saved questions manually or based on a schedule. You can also issue saved questions through Tanium modules or through custom applications that use the Tanium XML API. For example, you can use Tanium™ Connect to periodically issue a saved question and send the results to an external server. You create saved questions by issuing a dynamic question through the Question Bar and saving it. Tanium modules and content packs that you import also provide predefined saved questions. The Interact module organizes saved questions under dashboards and organizes dashboards under categories. Each category, dashboard, and saved question is assigned to one content set.
A dashboard is a group of saved questions that are related with respect to the information that they retrieve from endpoints. For example, the predefined Hardware Inventory dashboard contains questions that retrieve CPU, disk, memory, and BIOS information. You can issue all the questions in a dashboard simultaneously.
A category is a group of dashboards. It serves as an umbrella term for questions that you use for a particular purpose. For example, the Security category includes the Data Leakage, Wireless Network Security, and USB Device Security dashboards, all of which contain security-related questions.
A content set is a group of saved questions, dashboards, categories, and other content to which you apply user role permissions to control access. Tanium provides several predefined content sets through Initial Content packages and Tanium modules, and you can also create custom content sets. For details and related tasks, see Managing content sets.
After you use Tanium Interact to issue a dynamic question, the Question Results page opens and displays a grid with the answers (results) from endpoints. The page facilitates analyzing the results by providing display options such as live updates, filters, and charts. For details and related procedures, see Managing question results.
After you use Tanium Interact to issue a question, analyze the question results, and determine which endpoints require administrative action, you can deploy a package to those endpoints so that the Tanium Client can run the associated action. For the procedure, see Deploying actions.
This documentation may provide access to or information about content, products (including hardware and software), and services provided by third parties (“Third Party Items”). With respect to such Third Party Items, Tanium Inc. and its affiliates (i) are not responsible for such items, and expressly disclaim all warranties and liability of any kind related to such Third Party Items and (ii) will not be responsible for any loss, costs, or damages incurred due to your access to or use of such Third Party Items unless expressly set forth otherwise in an applicable agreement between you and Tanium.
Further, this documentation does not require or contemplate the use of or combination with Tanium products with any particular Third Party Items and neither Tanium nor its affiliates shall have any responsibility for any infringement of intellectual property rights caused by any such combination. You, and not Tanium, are responsible for determining that any combination of Third Party Items with Tanium products is appropriate and will not cause infringement of any third party intellectual property rights.
Last updated: 2/25/2020 4:22 PM | Feedback