In the results grid, an answer row is an aggregation of the computers that responded with the data shown. The Count column shows the number of Tanium™ Clients with that answer.
The grid displays the first 100 answer rows. You can change the number of rows in user preferences. Go to the logged in user link in the upper right corner, and select Preferences to display the configuration page.
As results come in, Live Updates in the results grid toolbar shows the percent of Tanium Clients that have reported results.
|Click the pause button to pause updates to the grid.|
|Click the play button to resume updates to the grid.|
Even when 100% of Tanium Clients have reported, you might see answer rows that seem to indicate incomplete results.
Indicates that the Tanium Client was instructed to answer but does not have a value that matches the sensor filter. This can be expected when a filter is applied to the get clause and not the from clause. For example, if the question is formed with the syntax Get IP Address ending with 2 from all machines, all machines would report answers and all machines that did not have IP address ending in 2 would report no results. It is better to put the filter in the from clause. For example, Get IP Address from all machines where IP Address ends in 2 would not return unexpected "no results" rows. You might also see [no results] if the sensor does not return a value, or the sensor was unable to execute the script.
[Current Result Unavailable]
If it takes the client longer than usual to evaluate a sensor, it might pass "current result unavailable" to its peer. The sensor process continues on the client, and when it is complete, the client sends its updated answer. The results grid is then updated.
[Results Currently Unavailable]
Indicates an answer cannot be parsed correctly by the Tanium Server. If this occurs, contact your technical account manager (TAM).
Use the filter controls to display only rows that match the specified criteria.
Filter by Text
Filters the results grid without reissuing the question. Select the Contains or Does not contain operator, specify a search string, and click the search icon.
Filter by Computer Group
Issue a new question with the added filter. Select from the wildcard groups All Computers, No Computers, configured computer groups, and the special Ad Hoc Filter. The Ad Hoc filter is a one-time only filter. The Ad Hoc filter configuration is not saved.
To create an ad hoc filter:
- Select Create Ad Hoc Filter from the Filter by Computer Group drop-down list.
Interact displays the Group Builder dialog box.
- Use one of the tabs to create a filter and then click Apply.
The Filter Builder tab includes fields that enable you to add a filter, apply it, and issue the resulting question. The question is always Get computer name and IP address from all machines with the filter added to the from clause.
In column headers, click the menu icon to display the menu for sorting rows and showing/hiding columns.
|Click the Clear Sort button to clear sorting criteria.|
The results grid is the default view. You can use the View button bar in the upper right corner to toggle to a pie chart or bar chart.
Mouse over a pie slice or bar to display the result string and count. If the result count is less than 3 % of the total, it is included in the Other group.
|Use the Copy Table icon to copy the results to the clipboard in text format. This action copies the complete results, not just the results displayed on the results grid.|
|Use the Export Table icon to export the results to a .csv file. This action exports the complete results, not just the results displayed on the results grid.|
|Select one or more rows and use the More selector to copy or export only the selected rows.|
You can use keyboard and mouse action combinations to copy the contents of grid cells from most grids in the Tanium Console, including the results grid. On Windows, press the Alt key and left click in the grid cell. On MacOS, press the Option key and click in the grid cell. A blue toast message notifies you that the cell contents has been copied to the clipboard.
Results often lead to additional questions. For example, let's say you originally ask for a list of computer names and running processes, and you see results that indicate a suspicious process is running on a few machines. You can merge the question with another to learn more—for example, the last logged-in user. The merge question is issued in the background, and the results grid is redisplayed with one or more additional columns that have data for the added sensor.
To merge questions:
- Click Merge in the upper right corner of the results grid toolbar.
Interact displays the Select Merge Questions dialog box.
- Use one of the tabs to add one or more questions and then click the red Merge button.
The Build a Question tab includes fields that enable you to select sensors for the merge question.
Notice that you add additional sensors to the "get" clause but you do not add filters to the "from" clause. The from clause is built from the rows that were selected on the results grid when you clicked Merge.
From the results grid, you can drill down from selected results to retrieve additional information from the selected endpoints. By adding a drill-down question, you are essentially adding sensor filters. You often will want to do this when you are targeting a narrow group of computers for an action. For example, let's say you originally ask for a list of chassis types and operating systems. You can drill down from these results to the list of computer names for the matching records.
To drill down:
- Select one or more rows in the results grid. When you select rows, the red Drill Down, Deploy Action, and More buttons are displayed.
- Click Drill Down.
Interact displays the Select Drilldown Question dialog box.
- Select or configure a question you want to use and then click the red Drill Down button.
Interact displays the progression of results, including a new results grid for the drill-down question. From here, you can drill down further, deploy an action, save the question, or copy it to the Question Bar or Question Builder for further refinement.
Last updated: 6/29/2018 1:18 PM | Feedback