Tanium Asset 1.5.2 Ug
Tanium Asset 1.5.2 Ug
Tanium Asset 1.5.2 Ug
Version 1.5.2
Any IP addresses used in this document are not intended to be actual addresses. Any
examples, command display output, network topology diagrams, and other figures included in
this document are shown for illustrative purposes only. Any use of actual IP addresses in
illustrative content is unintentional and coincidental.
Please visit https://docs.tanium.com for the most current Tanium product documentation.
Tanium is a trademark of Tanium, Inc. in the U.S. and other countries. Third-party trademarks
mentioned are the property of their respective owners.
Sources 8
Predefined reports 8
Report drilldown 9
Custom reports 9
Views 9
Data export 9
ServiceNow CMDB 9
Tanium™ Connect 9
Flexera 9
Getting started 11
Asset requirements 12
Tanium dependencies 12
Disk space 12
Third-party software 13
Ports 13
Internet URLs 13
Tanium 7.0 14
Import Asset 17
Verify installation 17
What to do next 20
Building reports 21
View reports 21
Filter report 22
Create a report 23
Select columns 24
Finish report 25
Delete report 25
Delete assets 25
Configuring sources 27
What to do next 28
Configuring attributes 30
View imports 35
Configuring views 37
Create views 37
Reserved views 38
CSV file 39
Tanium Connect 39
Create a connection 39
Asset Reports 39
Asset Computers 39
COMPATIBILITY 41
Examples 41
Example: Flattened JSON 42
ServiceNow CMDB 42
Run export 45
Troubleshooting Asset 50
Collect logs 50
Uninstall Asset 52
You can build reports to show an overview of all your assets, or you can drill down into
specific computers or users.
Sources
Asset uses saved questions in Tanium to get information about your endpoints to populate
the Asset database. These saved questions are run on a schedule to regularly update the
database.
In addition to pulling endpoint information from Tanium, you can import data from an
external database by defining a database source, and configuring mappings on where to
add the data in the Asset database.
You can augment Asset inventory data with external data from a SQL Server database. By
importing data that is typically not available on an endpoint into the Asset data store, you
can enable filtering and reporting on information such as department, cost center,
building, and location.
Predefined reports
Asset comes with a set of predefined reports to help you prepare for audit and inventory
activities.
l All Assets
l Physical Machine Summary
l Virtual Machine Summary
l Platform Summary
l All Users
l All Software
Report drilldown
If you create a summary report, you can drill down on the computer count and see a
filtered list of computer details, which includes the software and hardware information
about the asset.
Custom reports
You can build custom reports that are based on any existing report. You can also create
your own reports from existing Tanium sensor data or custom content. You might choose
to create custom reports to show assets by department, location, user group, or other
attributes.
Views
Use views to build an alternative perspective of the Asset data. Views specify available
attributes and can filter the included data. You can export data from a view to Tanium
Connect.
Data export
ServiceNow CMDB
Asset data can enrich the inventory data in ServiceNow CMDB, ensuring that it has up-to-
date information. With Asset, you can define the server, attribute mappings, and schedule
for data to be exported.
Tanium™ Connect
You can use any predefined reports, custom reports, or views as a connection source and
send to destinations such as Email, File, HTTP, Socket Receiver, Splunk, and SQL Server.
Flexera
With the Flexera integration, you can use the existing Tanium Client to populate
information in Flexera FlexNet Manager Suite (FNMS).
This documentation may provide access to or information about content, products (including hardware and software), and services provided by third parties
(“Third Party Items”). With respect to such Third Party Items, Tanium Inc. and its affiliates (i) are not responsible for such items, and expressly disclaim all
Further, this documentation does not require or contemplate the use of or combination with Tanium products with any particular Third Party Items and neither
Tanium nor its affiliates shall have any responsibility for any infringement of intellectual property rights caused by any such combination. You, and not Tanium,
are responsible for determining that any combination of Third Party Items with Tanium products is appropriate and will not cause infringement of any third party
intellectual property rights.
Tanium dependencies
In addition to a license for the Asset product module, make sure that your environment
also meets the following requirements.
Component Requirement
Disk space
Asset requires disk storage capacity necessary to support the number of endpoints in your
environment. For planning purposes, use 100 MB per 1000 endpoints, for example:
Usage might vary significantly based on the following variables: the number of endpoints,
the number of applications, the number of users, if file evidence data is enabled, and most
importantly the attributes that you add on the Inventory Management > Attributes page.
These suggested sizes are considered a good estimate for most environments.
Third-party software
The following third-party software is optional for exporting data from Asset:
l For the ServiceNow CMDB connector, the Jakarta release or later is required.
l For Flexera integration, you must have an SQL database that can be configured to
receive data from Asset. Ask your TAM for more information.
Ports
The following ports are required for Asset communication.
Internet URLs
If security software is deployed in the environment to monitor and block unknown URLS,
your security administrator might need to add the following URLs to the whitelist.
views
1 1 1
Show Asset
1 1
Asset Report Read
2
Asset Report Write
Table 3: Provided Asset Advanced user role permissions for Tanium 7.1.314.3071 or
later
Permission Content Set for Asset Asset Asset Report
Permission Administrator User Reader
Connect User (Connect 4.8 and later) Create, edit, or delete a Flexera destination
Tanium Administrator Create scheduled actions for the file evidence content for
Flexera destinations
Import Asset
Import Asset from the Tanium Solutions page.
Note: Tanium Asset is a licensed solution. If Tanium Asset is not on the Tanium
Solutions page, contact your Technical Account Manager.
l For platform version 7.1.314.3071 and later, enable Include content set
overwrite and click Proceed with Import.
For more information, see Tanium Core Platform User Guide: Align content for
modules.
4. After the installation process completes, refresh your browser.
5. From the Main menu, click Asset. The Asset home page is displayed.
Verify installation
To verify that Asset is installed, go to the Tanium Solutions page and check the installed
version. To check the installed version on the Asset home page, click Info .
1. In your Tanium Module Server machine, open the Services panel. Go to Control
Panel > Administrative Tools > Services.
2. Right click the Tanium Asset service, and select Properties.
3. In the Log On tab, specify the user with Administrator credentials that you want to
use to run the service.
4. Stop and restart the service to complete the update.
This database provides data for offline assets. You can create a standard interval or
1. From the Asset home page, click Settings .In the Advanced Settings tab, click
Create Scheduled Actions.
2. From the Main menu, go to Actions > Scheduled Actions.
3. Edit the Tanium Asset action group to include the computer group for which you
want to collect this information. By default, the Computer Group Targets setting is
set to No Computers. After you select a computer group, Asset further targets this
group to include Windows systems only.
4. The Asset Deploy Collect Active Directory Info action is listed in the action group.
You can configure this action to run the collection routine every few hours.
The Asset Deploy Collect Active Directory Info action gets recent sign ins and the primary
user of each system. A primary user has the most interactive sign ins the past 30 days. For
Mac and Linux endpoints, you do not need to deploy any actions to get this information.
Tip: If the Asset version is not updated, refresh your browser window.
What to do next
See Getting started on page 11 for more information about using Asset.
Filter report
You can perform live filtering on any report. Any filtering that you modify while you are
viewing a report is not saved in the report. If you want to create persistent filters, edit the
report and modify the filters in the report settings.
3. View filter details. Click Expand to view a JSON representation of the rule, which
can be helpful to evaluate complex filtering.
4. Update the report data. Click Refresh Report to refresh the report based on the
filters.
Create a report
You can create a report from an existing report, or you can create a new custom report:
l In an existing report, click Create Copy to create a copy of the report, and then
modify any details as needed.
l From the Reports page, click Create Custom Report.
Select columns
The columns that are available to include in your reports come from the asset sources that
you define. To define sources, click Inventory Management > Sources in the Asset menu.
1. In the Add Columns section, select the data that you want to include in your report.
You can search for the column that you want to use, or expand and collapse the data
categories to find which columns you want to include.
Click Add > Add Row to create a filter rule that is at the same level as the selected rule.
When you create the rule, you can choose whether the filter applies AND or OR operators
with the other filters at that level. To create nested groups of filters, click Add > Add
Row.
When you are done editing the filter, click Refresh Report.
Finish report
To save the report, click Create Report. After the report is created, you can click Edit
Report to modify the columns and default filters.
Delete report
To delete a report, go to the report page and click Delete .
Delete assets
You can remove assets from your asset database that are outdated or that you no longer
want to track.
This database provides data for offline assets. You can create a standard interval or
What to do next
Add attributes from Tanium sensors into Asset. See Configuring attributes on page 30.
IMPORTANT: If you use column types (like nchar) that pad values with spaces, your
identity mappings on the database source might not work correctly. For example, a
computer name like win1 might come through as win1 (with six spaces after
it). These values do not match a value win1 in Asset.
If you want to modify the source, go to Inventory Management > Sources. Click Edit . You
must enter the credentials for your SQL server again before you can modify the source
mappings.
What to do next
Add the attributes from your import table into Asset. See Configuring attributes on page 30.
When the data import runs, each row of your import table is evaluated data that is already
in Asset. For example, if you created a mapping for your computer ID in the import table,
that ID gets matched to the computer ID column in Asset. If a match is found, the attributes
that you configured to get imported from your source table are inserted into Asset. If you
map an import column that has duplicate values in the table, only the last value is stored in
Asset after the load has completed.
IMPORTANT: Remember that each attribute you add increases the number of saved
questions that are asked during the data import process. Each new attribute also
adds columns and data to the Asset database.
1. From the Asset menu, click Inventory Management > Attributes. Click New Attribute.
2. In the Source field, select Tanium. You can search for and select the sensor from
which you want to add attributes. To view all of the Asset custom content, you can
search for Asset in this sensor list.
IMPORTANT: This step makes changes to the Asset database. Review and verify
carefully.
4. After the database updates are completed, you can see the new attribute in the main
list of attributes in Pending state. The new attribute stays in pending state until the
next time the Asset Import Data Sources job runs, and data gets populated in the
database. To run this job immediately, see View schedule and run import on page 34.
When populated, the attribute displays in Ready state. You can add attributes that
are in Ready state to custom reports.
BIGINT BIGINT
DATE DATEONLY
IMPORTANT: This step makes changes to the Asset database. Review and verify
carefully.
5. After the database updates are completed, you can see the new attribute in the main
list of attributes in Pending state. The new attribute stays in pending state until the
next time the External database job runs, and data gets populated in the database.
To run this job immediately, see View schedule and run import on page 34. When
populated, the attribute displays in Ready state. You can add attributes that are in
Ready state to custom reports.
2. Click Run Now to override the schedule and have Asset immediately pull source data
into the Asset database.
If you want to change the import schedule, update the asset source. See Configuring
sources on page 27.
View imports
On the Asset home page, you can view a timeline of the recent imports and exports.
The timeline contains each import, with one of the following statuses:
l : Scheduled
l : Successful
l : Error
l : Running
Before you begin, you must have a user group to which you want to assign the Asset
permissions. See Tanium Core Platform User Guide: Managing user groups. For the users
in this user group to access Asset, they also must have an Asset user role assigned. See
User role requirements on page 14.
1. From the Asset home page, click Settings . Click the User Group Permissions tab.
2. Click Create User Group Permission.
3. Click Add User Groups. Select the user group from the list that you want to assign.
5. Click Save.
Create views
You can include fewer attributes than the default view, depending on the use of your view.
1. From the Asset menu, click Inventory Management > Views. Click New View.
2. Give your view a name and description to help you remember the purpose of the view
later. The view name must be unique among all views in Asset, including views
created by other users.
3. Select the attributes that you want to include in your view.
4. (Optional) Add filters to limit the computers that are included in the view. You can
create filters for Asset Details, Asset Installed Applications, Asset Logical Disk, Asset
Network Adapter, Asset Physical Disk, Asset Windows Installer Applications, or any
custom reference attributes that you have added to Asset.
Click Add
Reserved views
Reserved views are read-only. Click View to see the set of fields that are included in the
reserved view. If you want to customize the fields or filters, click Create Copy. Edit and
rename the view.
When you configure Tanium integration with ServiceNow, a reserved view is created. For
more information, see ServiceNow CMDB on page 42.
CSV file
You can copy data from an asset report table to the clipboard and paste the data in an
application that can interpret a CSV file, such as a database. Select the rows that you want
to copy and click Copy to Clipboard . You can then paste the information about the rows
you selected.
Tanium Connect
To export data from Asset to Connect destinations such as Email, File, HTTP, Socket
Receiver, Splunk, and SQL Server, create a connection.
Create a connection
With Connect 4.3 to 4.7, choose Asset Report as the connection source. You can choose a
predefined or custom Asset report as a connection source.
With Connect 4.8 and later, choose Tanium Asset as the connection source. You can
choose from the following types of Asset source:
ASSET REPORTS
Select any view as a connection source and export structured data using an Asset view.
If you do not enable Flatten Results, the entire data set that is retrieved for one computer
is a single record. For example, if you are exporting Installed Applications, a computer has
a single row with the entire list of installed applications in that same record. Any change
l If you enable Enhanced JSON, you must also choose JSON as the format for your
connection.
l To customize the column names, expand the Columns section and click Add or
Modify Columns. Change the display values in the Destination column as needed.
l If you customize the columns, leave the Value Type as Unmodified to get the
expected object output.
COMPATIBILITY
Use the following recommendations for Enhanced JSON and Flatten Results settings for
each format in Connect. If you use an unsupported combination, connection failures might
occur or incorrect data might get written to the destination.
EXAMPLES
Compare the data that is returned from Asset installed applications. View JSON examples
{
"Computer Name": "WIN-2012-R2",
"Asset Installed Applications": [{
"name": "Tanium Server 7.2.314.3019",
"version": "7.2.314.3019",
"vendor": "Tanium Inc."
}, {
"name": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026",
"version": "14.0.23026.0",
"vendor": "Microsoft Corporation"
}, {
"name": "Microsoft SQL Server 2012 Native Client",
"version": "11.3.6540.0",
"vendor": "Microsoft Corporation"
}]
}
EXAMPLE: FLATTENED JSON
[{
"computer name": "WIN-2012-R2",
"name": "Tanium Server 7.2.314.3019",
"vendor": "Tanium Inc.",
"version": "7.2.314.3019"
}, {
"computer name": "WIN-2012-R2",
"name": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026",
"vendor": "Microsoft Corporation",
"version": "14.0.23026.0"
}, {
"computer name": "WIN-2012-R2",
"name": "Microsoft SQL Server 2012 Native Client",
"vendor": "Microsoft Corporation",
"version": "11.3.6540.0"
}]
For more information about creating connections, see Tanium Connect User Guide.
ServiceNow CMDB
Before you begin
l You must be using ServiceNow Jakarta release or later. ServiceNow Software Asset
Management Pro is also supported.
IMPORTANT: Test the data export against a copy of your ServiceNow instance before
you configure Tanium Asset to export all data to your production instance of
ServiceNow. Because the built in identification rules in Service now assume unique
computer names or serial numbers, you might need to add one or more
identification rules to achieve consistent and expected results.
The ServiceNow (reserved) view includes all computers. Create a view with filters enabled if
you want to narrow the scope of the export.
From the Asset menu, click Inventory Management > Destinations > ServiceNow. Click Edit
. In the ServiceNow Export Mapping section, you can add and edit individual mappings.
Work with your TAM to properly edit the ServiceNow export mappings.
Run export
You can run an export to ServiceNow CMDB outside of the configured schedule. From the
Asset menu, click Inventory Management > Schedules. Under your ServiceNow destination
in the Asset Export Destinations section, click Run Now.
Click Get Schemas. When you click this button, a connection is established with the
SQL server that looks for databases that match the basic required schema to export
Asset data. If a database matches these requirements, it is displayed in the Database
and Schema fields.
4. Click Create.
l Additional attributes are added to Asset. These attributes will be pending until the
next Tanium import. See View schedule and run import on page 34 for more
information.
l Flexera reports are created in Asset. View these reports in the Reports section under
Custom Reports. Do not delete or modify these reports. Modifying these reports
disrupts the Flexera export.
Use Connect for all troubleshooting of the data transfer to the SQL server. Each Flexera
connection contains information about the schedule and success or failure of the data
transfer.
1. Install Tanium Index and verify that endpoint file systems are being indexed. The
Distribute Tanium Index Tools , Distribute Tanium Index Config and Start Indexing
packages must be deployed to the endpoints and the Index Status sensor should
return Running. For more information, see Tanium Incident Response User Guide:
3. Deploy the Asset Start File Evidence Scan package to your endpoints. From Interact,
target a set of endpoints to gather file evidence from which the Asset File Evidence
Status sensor returns Installed. Click Deploy Action and create an action that
deploys the Asset Start File Evidence Scan package. To ensure that the scan is
restarted when a computer restarts, configure the saved action as a scheduled action.
4. When everything is configured, the Flexera Report File Evidence custom report
begins to get populated with data.
Collect logs
The information is saved as a compressed ZIP file that you can download with your
browser.
1. From the Asset home page, click Help , then the Troubleshooting tab.
2. Collect the troubleshooting package. Click Collect. To collect additional information
Postgres table statistics that includes information bad tuples, live, last vacuum, and
so on, click Collect Detailed. When the ZIP file is ready, you can download the
tanium-asset-support-[timestamp].zip file to your local download
directory.
3. Attach the ZIP file to your Tanium Support case form or send it to your TAM.
The timeline contains each import, with one of the following statuses:
l : Scheduled
l : Successful
l : Error
l : Running
ServiceNow exports
You can use these logs to view details about the scheduled runs that are occurring to
import asset data from Tanium into your Asset database.Tanium data import logs are
named with the following format: job/date_time_job#_tanium_1.log. For
data you are importing from a database, import logs are named with the following
1. From the Asset home page, click Settings , then the Data Settings tab.
l To purge stale assets that have not been seen by Asset from the database,
select Purge Stale Assets. Then, indicate the age of stale data to remove. The
minimum number is seven days.
l To adjust the trigger and amount of work done during automatic vacuuming,
adjust the Cost Limit and Size Factor values. The Postgres VACUUM operation
reclaims storage that is occupied by dead tuples. By default, the database is
vacuumed when 1% of tuples are considered dead, and the cost limit (amount
of work per vacuum cycle) is set to 1000.
2. Click Save.
Uninstall Asset
1. From the Main menu, click Tanium Solutions. Under Asset, click Uninstall. Click
Proceed with Uninstall to complete the process.
2. Delete any remaining Asset-related scheduled actions and action groups.
3. Remove Asset Tools from your endpoints. To see which endpoints have the file
evidence tools installed, ask the question: Get Asset File Evidence Status from
all machines. If you want to clean the artifacts from your endpoints, contact your
TAM.
4. A backup asset-files folder gets created as part of the uninstall process. You
can keep or delete this folder. If any other Asset artifacts remain on your Module
Server, contact your TAM.
Each asterisk is a field that must be included in the Cron expression. The field value can
either be an asterisk (any value) or one of the following values:
second 0-59
minute 0-59
hour 0-23
month 1-12