Tanium
Tanium is a unified endpoint management and security platform that provides real-time visibility, control, and management of endpoints across an organization's IT infrastructure. As a comprehensive endpoint detection and response (EDR) and IT operations solution, Tanium enables organizations to monitor, secure, and manage all endpoints including workstations, servers, laptops, desktops, virtual machines, and cloud instances at enterprise scale.
| Category | EDR |
| Direction | Query source |
| Sign-in | None |
| Query languages | STIX |
| Website | tanium.com |
Before you start
The setup page can't take credentials for Tanium yet. Create the connection, then contact Huntbase support to finish signing it in.
- If you leave Expiration empty, the token lasts 7 days. The maximum is 365 days by default.
- After five minutes, or once you leave or refresh the page, the token value can no longer be viewed.
- A token has the permissions of the account or persona it is bound to. Tanium recommends binding tokens to a service account.
For the vendor's own instructions, see Tanium API token documentation.
Connect Tanium
- Go to Connections and click New connection, or click New connection on the Tanium product page.
- On Product, pick Tanium and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Tanium lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your Tanium instance. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
Query it
Once connected, Tanium can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog