Performance overview

With Performance, you can monitor, investigate, and remediate endpoint performance problems.

Configure profiles to define events for specified computer groups. You can define event rules to monitor critical metrics related to hardware resource consumption, application health, and system health.

You can visualize the problems that have occurred across your environment and the commonalities between them on the Events page. Proactively resolving these problems can improve end-user productivity.

To troubleshoot an issue with a single endpoint, use Tanium™ Direct Connect. There, you can view live and historical process-level data from a single endpoint. This data can help you quickly troubleshoot or understand the impact of software and hardware changes on performance.

Profiles and Events

Profiles define events for specified computer groups. For each profile, you can select computer groups to monitor and rules that determine when an event occurs.

Events are generated when an endpoint experiences the conditions that you defined in an event rule in a profile.

When a profile targets an endpoint, tools are distributed to that endpoint to collect and monitor performance data. Data is collected every 15 seconds and stored for 15 days. This local data store is queried when you analyze events in Performance.

For example, you might want to know when available memory falls below a certain threshold on specific computers. You can create a profile with an Available Memory is less than 250 MB event rule and set the target for that profile to a computer group you want to monitor. When you analyze events in Performance, memory events are reported if any endpoints that you are targeting had less than 250 MB of available memory during the time frame (scope) that you selected for analysis.

The Events page displays charts that provide a high-level overview of events in the environment. You can also see a list of the specific endpoints that experienced a particular event (such as low memory) to identify and investigate issues in your environment. For more information, see Analyzing events.

Event rules

Event rules determine what conditions cause targeted endpoints to report events. Performance includes these event rules:

  • Application Crashes
  • Available Memory
  • CPU Critical
  • Disk Capacity
  • Disk Latency
  • System Crashes

You can select heuristics for some event rules. For example, if you add the Disk Latency event rule, you can monitor Read Latency or Write Latency. If either heuristic is reached, the event rule is triggered.

For more information, see Reference: Event rules.

Integration with other Tanium products

Performance integrates with other Tanium products to provide additional features and reporting.

Direct Connect

Use Direct Connect to view live and historical data on endpoints to troubleshoot issues. For more information, see Connecting directly to endpoints.


Performance has built in integration with Tanium™ Trends for additional reporting of related data. The Trends initial gallery features a board that provides data visualizations of Performance concepts.

Performance board

Contains a Performance Events panel that displays the Performance events that occurred in the past 30 days. Also includes an Event Composition panel, which displays the number of Performance events that were reported in the past day broken down by type of event: Available Memory, CPU Critical, Disk Capacity, Disk Latency, and System Crashes.

For more information about how to import the Trends boards that are provided by Performance, see Tanium Trends User Guide: Importing the initial gallery.