Managing content sets
Content sets overview
A content set is a group of sensors, saved questions, packages, dashboards, categories
The following figure shows the relationship between contents sets and content, permissions, and roles.
For details about roles, see Managing roles.
To see and use the Content Sets or Content Alignment pages, and to import or export content set and role configurations, you must have the Administrator or Content Set Administrator reserved role, or a custom role with administrator or content set administrator permissions.
Go to the Permissions > Content Sets page to review and manage content sets. Use the filtering text box to filter the items by content set name
- Go to Permissions > Content Sets and click New Content Set.
- Specify a configuration Name and Description, and click Save.
- Click Preview to Save and click Confirm & Save.
Move content between content sets as necessary to accommodate changes to the RBAC configuration of your Tanium deployment. For example, if a sensor collects sensitive information from endpoints, you might want to move that sensor to a content set that only highly privileged user roles can access. Before moving content, be sure that you understand how the move affects workflows. For example, if a user configures a scheduled action, and you later move the associated package to a content set for which that user does not have permission, the Tanium Server will not deploy the action. For the predefined content that is included in Tanium modules and content packs, the best practice is to keep that content in the original predefined content sets. As much as possible, create copies of Tanium-provided content and move the copies to other content sets when necessary. If moving original Tanium-provided content becomes necessary, consult your Tanium Technical Account Manager (TAM) before proceeding.
You can move content between any content sets except:
- The Reserved content set, which includes fundamental sensors that the Tanium Core Platform uses.
- Certain Tanium solution module-based content sets.
Perform the following steps to move content:
- Go to Permissions > Content Sets and expand the content set that contains the content you want to move.
- Select the content that you want to move.
- Click Move to and select the target content set.
- Click Preview to Save and review your changes.
- Click Confirm & Save.
Because the Content pages have descriptions of the sensors, packages, saved questions, and filter groups, you might find it helpful to use the Content pages for moving content to familiarize yourself with the content first. For example, when you select one or more sensors in the Content > Sensors page, the Move to Content Set button appears above the table. You can also move content through the Content Set drop-down list when modifying content (see Specify a content set when you create or edit content). You can move content between content sets for which you have write permission. Users with the Administrator or Content Set Administrator reserved role can move content between any content sets except the Reserved content set and certain module-based content sets.
When creating or editing content, you use a drop-down list to select the associated content set. The Content Set drop-down list includes only the content sets for which you have write permission. The following example shows the drop-down list for a sensor (go to Content > Sensors and click New Sensor).
When modifying or troubleshooting the RBAC configuration of your Tanium deployment, it is useful to know which
- Go to Permissions > Content Sets and expand the content set that you want to review.
- Find the content (such as a sensor) that you want to review.
- Click the appropriate icon to open a dialog that displays the
roles orusers or user groups that have permissions for the content.
- Click OK to close the dialog.
As a best practice, test content sets and roles in your lab before importing their configuration into your production environment. The configuration that you export and import is file that specifies the settings for content sets and roles.
- Go to any Content or Permissions page and click Export Content at the top right of the page.
- Select Content Sets and Roles
, select the Export Format (JSON or XML),and click Export.
- Enter a File Name or use the default name, and then click OK. The Tanium Server exports the content file to the Downloads folder on the system that you use to access the Tanium Console.
You can import files that are in JSON or XML format.
- Digitally sign the content file and ensure a public key is in place to validate the signature, as described under Authenticating content files.
- Go to any Content or Permissions page and click Import Content at the top right of the page.
- Click Choose File, find and select the configuration file, and click Open.
- Click Import. If object names in the file are the same as for existing objects, the Tanium Console itemizes the conflicts and provides resolution options for each one.
- Select resolutions for any conflicts. For guidance, see Conflicts and Best practices, or consult your TAM.
- Click Import again, and click Close when the import finishes.
You must empty a content set configuration before you can delete it.
- Go to Permissions > Content Sets and move all the objects from the content set that you want to delete: see Move content between content sets.
- Click Delete at the top right of the content set tile.
Some Tanium solution modules require module-specific sensors, packages, and saved questions to remain in their module-specific content sets. Moving that content might disrupt the module workflow. Modules report misaligned content to the Content Alignment page. To realign content:
Last updated: 4/2/2020 7:12 PM | Feedback