Requirements

This topic summarizes the requirements for installing Tanium Core Platform servers.

For the host system requirements of the Tanium Client, see Tanium Client Management User Guide: Tanium Client and Client Management requirements.

Installation package and license files

Tanium provides the following installation package files and license file required to install the Tanium Server, Tanium Module Server, and Tanium Zone Server:

  • SetupServer.exe
  • SetupModuleServer.exe
  • SetupZoneServer.exe
  • tanium.license

The installation package for each of these three servers must have the same build number (for example, all must have build number 7.4.5.1200). To complete the procedures in this guide, be sure you can copy these files to, and between, the host computers.

The license is bound to the hostname you assign to the Tanium Server. In high availability (HA) deployments, the license must specify the hostnames of both Tanium Servers. Contact Tanium Support if the server hostnames change.

Server version and host system requirements

Table 1 summarizes basic requirements for Tanium Core Platform and database servers that are installed on customer-provided Windows infrastructure. For detailed version specifications and sizing guidelines, see Reference: Host system resource guidelines.

Tanium solutions (modules and shared services) might have additional requirements for Tanium Core Platform servers. Table 2 provides links to the user guide sections that list these requirements.

The Standard, Enterprise, and Datacenter editions of the following Windows Server platforms are supported. The Server Core and Nano Server options are not supported.

 Table 1: Server hardware and software requirements
Server Hardware Operating System Software
Tanium Server CPU cores: 8 to 80
Memory: 32 to 512 GB
Disk: 250 GB to 3 TB
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
A web browser is required to use Tanium Console: see Tanium Console User Guide: Web browser requirements.
Database Server CPU cores: 4 to 32
Memory: 8 to 48 GB
Disk: 150 GB to 750 GB
Database size: 20 GB to 500 GB
Disk array IOPS: 100 to 1000
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
  • Microsoft SQL Server 2019 (Tanium 7.2 and later)
  • Microsoft SQL Server 2017 (Tanium 7.2 and later)
  • Microsoft SQL Server 2016
  • Microsoft SQL Server 2014
  • Microsoft SQL Server 2012
  • PostgreSQL Server 9.5 and later (Contact Tanium Support for guidance on host computer specifications and PostgreSQL Server version specifications.)
Tanium Module Server CPU cores: 8 to 80
Memory: 32 to 512 GB
Disk: 150 GB to 300 GB
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
 
Tanium Zone Server CPU cores: 8 to 80
Memory: 16 to 256 GB
Disk: 250 GB to 3 TB
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
 

Click the links in the following table to see the minimum Tanium Core Platform version (Tanium dependencies) and other platform server requirements for each Tanium module and shared service.

 Table 2: Solution-specific requirements for Tanium Core Platform servers
Product Tanium Dependencies Server Requirements
Asset Tanium dependencies Tanium Module Server
Client Management Tanium Client Management dependencies Compatibility between Tanium Core Platform servers and Tanium Clients
Comply Tanium dependencies No additional requirements
Connect Tanium dependencies Tanium Module Server
Deploy Tanium dependencies Tanium Server and Module Server
Direct Connect Tanium dependencies Tanium Module Server

Zone proxy server requirements

Discover Tanium dependencies Tanium Module Server
Endpoint Configuration Tanium dependencies Tanium Module Server
End-User Notifications Tanium dependencies Tanium Module Server
Enforce Tanium dependencies No additional requirements
Health Check Tanium dependencies Tanium Module Server
Impact Tanium dependencies Tanium Module Server
Integrity Monitor Tanium dependencies No additional requirements
Interact Tanium dependencies No additional requirements
Map Tanium dependencies Tanium Module Server
Network Quarantine Tanium dependencies Tanium Module Server
Patch Tanium dependencies Tanium Server and Module Server computer resources
Performance Tanium dependencies No additional requirements
Reputation Tanium dependencies Tanium Module Server
Reveal Tanium dependencies Tanium Module Server
Threat Response Tanium dependencies Tanium Module Server
Trends Tanium dependencies Tanium Module Server

Tanium Core Platform server and client compatibility

Tanium Clients can connect only to Tanium Core Platform servers (Tanium Server, Tanium Module Server, and Tanium Zone Server) that run the same Tanium™ Protocol version as the clients or a later version than the clients. Servers and clients at version 7.3 or earlier run Tanium Protocol 314. Servers and clients at version 7.4 or later run Tanium Protocol 315. Effectively, this means that servers are backward-compatible with earlier clients; for example, servers at version 7.4 support Tanium Client 7.2, but Tanium Client 7.4 cannot connect to servers at version 7.2.

For details about the Tanium Protocol, see Tanium Core Platform Deployment Reference Guide: Overview of TLS in the Tanium Core Platform.

The release numbers for Tanium Core Platform servers and Tanium Clients have the format <major release>.<minor release>.<point release>, such as 7.4.5. Clients can connect to the servers when their major and minor release numbers match regardless of whether the point release numbers match. For example, Tanium Client 7.4.5 can connect to Tanium Server 7.4.2.

  • To ensure that all the features and fixes in a release are available to Tanium Core Platform servers and Tanium Clients, upgrade both to the same major, minor, and point release.

  • Do not install the Tanium Client on the same host as a Tanium Core Platform server. If you choose to install the client on Tanium Core Platform server machines, you must take precautions to prevent these servers from being targeted in endpoint actions that might be disruptive to the Tanium environment, and to prevent unauthorized users from accessing the servers as endpoints. You cannot install the client on a Tanium Appliance, and you cannot use Tanium Client Management to install the client on the Tanium Module Server.

Internet access, network connectivity, and firewall

Tanium components use TCP/IP to communicate over IPv4 and IPv6 networks. Tanium Core Platform 7.2 and earlier supports only IPv4. Contact Tanium Support if you need IPv6 support in version 7.3 or later. You must work with your network administrator to ensure that the Tanium components are provisioned with IP addresses and can use DNS to resolve host names.

During installation and ongoing operations, the Tanium Server and the web browser that you use to access the Tanium Console must connect to https://content.tanium.com to import updates to Tanium Core Platform components and modules. The Tanium Server might need to connect to additional URLs based on the components you import. For a list of the required URLs, see Tanium Core Platform Deployment Reference Guide: Internet URLs required.

The Tanium Server must be able to connect to the Tanium database server and Module Server. In an HA deployment, the Tanium Servers must be able to connect to each other over a reliable Ethernet connection. All these connections require a minimum throughput of 1 Gbps and a maximum round-trip latency of 30 ms.

If your enterprise network environment requires outbound Internet connections to traverse a proxy server, you can configure the proxy settings as described under Tanium Console User Guide: Configuring proxy server settings.

The following table summarizes the Tanium processes and default values for ports used in Tanium Core Platform communication. Host and network firewalls might require configuration to allow the specified processes to send and receive TCP data over the listed ports. The Tanium installer opens required ports in the Windows host firewall. You must work with your network security administrator to ensure the platform components can communicate through any security barriers (such as firewalls) in their communication path. For a detailed explanation, see Tanium Core Platform Deployment Reference Guide: Network ports. Your security administrator might also need to create rules to exempt or exclude Tanium processes that run on the host computers from blocking by antivirus or processing by encryption or other security and management stack software. For details, see Tanium Core Platform Deployment Reference Guide: Host system security exceptions.

Configure firewall policies to open ports for Tanium traffic with TCP-based rules instead of application identity-based rules. For example, on a Palo Alto Networks firewall, configure the rules with service objects or service groups instead of application objects or application groups.

Network communication ports used by Tanium components
Source Destination Port Protocol Purpose
Tanium Server,
Module Server
External servers 443, 80 TCP Tanium Server (TaniumReceiver.exe) or Module Server (TaniumModuleServer.exe) communication with external servers such as content.tanium.com
Tanium Server Tanium Server 443, 17472 TCP Communication between active-active Tanium Servers
Tanium Server Module Server 17477 TCP Tanium Server communication with the Module Server
Tanium Server Tanium database 1433, 5432 TCP Tanium Server communication with the Tanium database: SQL server (Sqlservr.exe) or PostgreSQL server (postgres.exe)
Zone Server Hub Zone Server* 17472 TCP Zone Server Hub (TaniumZoneServer.exe) communication with the Zone Server (TaniumZoneServer.exe)
Tanium Clients Tanium Clients,
Tanium Server,
Zone Server*
17472 TCP Communication between Tanium Clients (TaniumClient.exe),
Communication between the clients and the Tanium Server or Zone Server
Console/API users Tanium Server, external servers 443   Tanium Console web traffic
Module Server Tanium Server 443   Tanium Module Server communication with the Tanium Server

To improve the security of the Zone Server, configure separate ports for traffic from Zone Server Hubs and Tanium Clients. For the steps, see Configure ports for traffic from Zone Server Hubs and Tanium Clients.

The following figure illustrates how the Tanium Core Platform uses ports in an active-active deployment with Windows infrastructure:

Figure  1:  Network communication ports

SSL/TLS certificates

SSL/TLS certificate and key exchanges secure connections to the Tanium™ Console or Tanium™ API, as well as connections between the Tanium Server and Tanium Module Server. When you run the server installation wizards, they prompt you to generate a self-signed certificate or specify the location of a certificate that was issued by a commercial certificate authority (CA) or your own enterprise CA. As a best practice to facilitate troubleshooting, use the self-signed certificates during initial installation and replace them with CA-issued certificates later. This practice enables you to separate potential installation issues from TLS connection issues. For details, see Tanium Core Platform Deployment Reference Guide: Securing Tanium Console, API, and Module Server access.

Administrator account permissions

Work with your Microsoft Active Directory (AD) administrator to provision the accounts needed during Tanium Core Platform installations or upgrades and for post-installation or post-upgrade activities.

Administrator accounts for installations and upgrades

The following table lists the administrator accounts required to install or upgrade Tanium Core Platform servers, create Tanium databases, or deploy Tanium Clients. You can use a single service account to install the Tanium Server and to create databases on the SQL or PostgreSQL server, as long as the account has the all required group memberships and permissions for those servers. You can also use a single service account to install the Zone Server and Zone Server Hub. You must use a separate service account to install the Module Server.

 Table 3: Administrator account permissions required for installations and upgrades
Service Account Type Host System Required Group or Permissions Account Purpose
Tanium Server and Tanium databases AD service account* Tanium Server host Administrator, interactive sign in This service account installs and upgrades the Tanium Server software.
SQL Server host Sysadmin on the SQL instance When running the installer from the Tanium Server, this service user connects remotely to the SQL Server and creates the tanium and tanium_archive databases.
PostgreSQL Server host Administrator When running the installer from the Tanium Server, this service user connects remotely to the PostgreSQL Server and creates the tanium and tanium_archive databases.
Tanium Module Server AD service account* Tanium Module Server host Administrator This service account installs and upgrades the Tanium Module Server software.
Tanium Zone Server and Zone Server Hub Local user or AD Tanium Zone Server host Administrator, interactive sign in This service account installs and upgrades the Tanium Zone Server software.
Tanium Zone Server Hub host Administrator, interactive sign in This service account installs and upgrades the Tanium Zone Server Hub software.
Tanium Client Local System or AD Tanium Client Deployment Tool host Administrator This account connects to endpoints and installs and upgrades Tanium Client software.
*It is possible to use the Local System account in a POC deployment, but not in a production deployment.

Administrator accounts for post-installation/upgrade activities

The following table lists the administrator accounts required for regular, ongoing operations performed after installations or upgrades, including running the services for Tanium Core Platform servers and Tanium Clients, and accessing Tanium databases. If you reuse the accounts used for installations and upgrades, first reduce the account permissions to those specified in the following table. You can use a single service account to run the Tanium Server service and access the Tanium databases. You can also use a single service account to run the Zone Server and Zone Server Hub services. You must use a separate service account to run the Module Server service.

 Table 4: Administrator account permissions required for post-installation/upgrade activities
Service Account Type Host System Required Group or Permissions Account Purpose
Tanium Server and Tanium databases AD service account* Tanium Server host User-level permissions This service account runs the Tanium Server service. The service runs in the context of the Local System or the AD account, depending on the option you select when installing the server.
SQL Server host DBO on Tanium databases This service user account accesses the tanium and tanium_archive databases. If you use the same account for running the Tanium Server service, the account must be able to connect remotely to the SQL Server. The account requires db_owner role membership for the Tanium databases. Assign the View server state permission as a best practice to enable the Tanium Server to access data faster than the DBO role alone.
PostgreSQL Server host User-level permissions This service user account accesses the tanium and tanium_archive databases. If you use the same account for running the Tanium Server service, the account must be able to connect remotely to the PostgreSQL Server.
Tanium Module Server AD service account* Tanium Module Server host Administrator This service account runs the Tanium Module Server service. The service runs in the context of the Local System account.
Tanium Zone Server and Zone Server Hub Local user or AD Tanium Zone Server host User-level permissions This service account runs the Tanium Zone Server service. The service runs in the context of the Local System or the AD account, depending on the option you select when installing the server.
Tanium Zone Server Hub host User-level permissions This service account runs the Tanium Zone Server Hub service. The service runs in the context of the Local System or the AD account, depending on the option you select when installing the server.
Tanium Client Local System Tanium Client Deployment Tool host Administrator On Windows, the Tanium Client service runs in the context of the Local System account.
*It is possible to use the Local System account in a POC deployment, but not in a production deployment.