Managing content sets
Content sets overview
A content set is a group of sensors, saved questions, packages, dashboards, categories, filter groups, and plugins to which a permission applies. Tanium provides several predefined content sets through the Default Content pack and Tanium solution modules. You can create a content set to contain custom content or to accommodate changes in the role-based access control (RBAC) configuration of your Tanium deployment. For example, you can create a content set for sensors and packages related to Tanium Client maintenance, and then configure roles that grant a wide group of users read access to the content but write access to a smaller group of users. You can assign content to only one content set. A role can specify permissions for multiple content sets. Configure advanced roles to define content set permissions across modules. For modules such as Tanium Trends that have module-specific content, you can configure module roles that define permissions for those content sets.
The following figure shows the relationship between contents sets and content, permissions, and roles.
For details about roles, see Managing roles.
To see and use the Content Sets
- From the Main menu, go to Administration > Permissions > Content Sets.
- (Optional) For modules that have module-specific content (such Tanium Trends), select a module in the Content for drop-down menu. The content sets on the page then show only the content types associated with that module.
By default, the menu is set to Platform so that the content sets display the content types that are common to the entire Tanium Core Platform: sensors, saved questions, packages, filter groups, dashboards, categories, and plugins.
- (Optional) Use the Filter Results fields to filter the items that the page displays:
- Filter by text: To filter the grid by the names of content sets or content objects, enter a text string in the Filter Content Sets field.
- Filter by runtime threshold: Filter the page by runtime threshold so that the listed sensors include only those that have exceeded a threshold. Expand the Filter Results section and select a threshold.
The current release supports runtime indicators only for sensors. Ignore the Question runtime thresholds. For details on runtime thresholds, see Managing sensor runtime thresholds.
- From the Main menu, go to Administration > Permissions > Content Sets and click New Content Set.
- Specify a configuration Name and Description, and click Save.
- Click Preview to Save and click Confirm & Save.
Move content between content sets as necessary to accommodate changes to the RBAC configuration of your Tanium deployment. For example, if a sensor collects sensitive information from endpoints, you might want to move that sensor to a content set that only highly privileged user roles can access. Before moving content, be sure that you understand how the move affects workflows. For example, if a user configures a scheduled action, and you later move the associated package to a content set for which that user does not have permission, the Tanium Server will not deploy the action. For the predefined content that is included in Tanium modules and content packs, the best practice is to keep that content in the original predefined content sets. As much as possible, create copies of Tanium-provided content and move the copies to other content sets when necessary. Contact Tanium Support before proceeding if moving original Tanium-provided content becomes necessary.
You can move content between any content sets except:
- The Reserved content set, which includes fundamental sensors that the Tanium Core Platform uses.
- Certain Tanium solution module-based content sets.
Perform the following steps to move content:
- From the Main menu, go to Administration > Permissions > Content Sets and expand the content set that contains the content you want to move.
- Select the content that you want to move.
- Click Move to and select the target content set.
- Click Preview to Save and review your changes.
- Click Confirm & Save.
Because the Content pages have descriptions of the sensors, packages, saved questions, and filter groups, you might find it helpful to use the Content pages for moving content to familiarize yourself with the content first. For example, when you select one or more sensors in the Content > Sensors page, the Move to Content Set button appears above the table. You can also move content through the Content Set drop-down list when modifying content (see Specify a content set when you create or edit content). You can move content between content sets for which you have write permission. Users with the
When creating or editing content, you use a drop-down list to select the associated content set. The Content Set drop-down list includes only the content sets for which you have write permission. The following example shows the drop-down list for a sensor (go to Administration > Content > Sensors and click New Sensor).
When modifying or troubleshooting the RBAC configuration of your Tanium deployment, it is useful to know which roles or users or user groups currently have permissions to access different types of content in a content set.
- From the Main menu, go to Administration > Permissions > Content Sets and expand the content set that you want to review.
- Find the content (such as a sensor) that you want to review.
- Click the appropriate icon to open a dialog that displays the roles or users or user groups that have permissions for the content.
- Click OK to close the dialog.
Export content sets and roles
- From the Main menu, go to Administration > Permissions > Content Sets and click Export Content.
- Select Content Sets and Roles, select the Export Format (JSON or XML), and click Export.
- (Optional) Edit the export File Name.
- Click OK.
The Tanium Server exports the content file to the downloads folder on the system that you used to access the Tanium Console.
Import content sets and roles
You can import content files that are in JSON or XML format.
- Digitally sign the content file and ensure a public key is in place to validate the signature. See Authenticating content files.
- From the Main menu, go to Administration > Configuration > Solutions.
- Scroll to the Content section and click Import Content.
- Click Choose File, select the content file, and click Open.
- Click Import.
If object names in the file are the same as for existing objects, the Tanium Console itemizes the conflicts and provides resolution options for each one.
- Select resolutions for any conflicts. For guidance, see Conflicts and Best practices.
- Click Import again, and click Close when the import finishes.
You must empty a content set configuration before you can delete it.
- From the Main menu, go to Administration > Permissions > Content Sets and move all the objects from the content set that you want to delete: see Managing content sets.
- Click Delete at the top right of the content set tile.
Some Tanium solution modules require module-specific sensors, packages, and saved questions to remain in their module-specific content sets. Moving that content might disrupt the module workflow. Modules report misaligned content to the Content Alignment page. To realign content:
Last updated: 2/11/2021 3:37 PM | Feedback