Tanium Discover
- 4 Minutes To Read
-
Print
-
DarkLight
The Tanium Discover adapter scans for unmanaged assets with almost no impact on the network.
Parameters
- Hostname or IP Address (required) - The Hostname or IP address of the Tanium server that Axonius can communicate with via the Required Ports.
- User Name and Password (required) - The credentials for a user account that has the Required Permissions to fetch assets.
- Fetch Unmanaged (required, default: True) - Fetch assets from Discover > Interfaces > Unmanaged.
- Fetch Unmanageable (required, default: True) - Fetch assets from Discover > Interfaces > Unmanageable.
- Fetch Managed (required, default: False) - Fetch assets from Discover > Interfaces > Managed.
- Fetch Ignored (required, default: True) - Fetch assets from Discover > Interfaces > Ignored.
- Verify SSL (required, default: False) - Verify the SSL certificate offered by the value supplied in Hostname or IP Address. For more details, see SSL Trust & CA Settings.
- If enabled, the SSL certificate offered by the value supplied in Hostname or IP Address will be verified against the CA database inside of Axonius. If the SSL certificate can not be validated against the CA database inside of Axonius, the connection will fail with an error.
- If disabled, the SSL certificate offered by the value supplied in Hostname or IP Address will not be verified against the CA database inside of Axonius.
- HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the value supplied in Hostname or IP Address.
- If supplied, Axonius will utilize the proxy when connecting to the value supplied in Hostname or IP Address.
- If not supplied, Axonius will connect directly to the value supplied in Hostname or IP Address.
- For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
- Trust Tanium Discover hostname (required, default: False) - Select whether to consider the Tanium Discover hostname value as the device hostname.
- If enabled, all connections for this adapter will set the Aggregated:Host Name with the fetched Tanium Discover:Discover Hostname field value.
- If disabled, all connections for this adapter will not set the Aggregated:Host Name with the fetched Tanium Discover:Discover Hostname field value.
- Number of assets to fetch per page (required, default: 100) - Control the number of assets that are fetched per page.
- Number of seconds to wait in between each page fetch (required, default: 1) - Control the number of seconds to wait in between each page.
For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.
Required Ports
Axonius must be able to communicate with the value supplied in Hostname or IP Address via the following ports:
- TCP port 443: REST API
Required Permissions
Required Module Permissions
A Module Role named Discover Read Only User exists that provides these Module Permissions:
- Show Discover
- Discover Asset Read
Assigning Required Permissions
These are the steps to assign the Required Permissions to the value supplied in User Name:
- Log in to the value supplied in Hostname or IP Address with an account that has the permissions necessary to edit users.
- In the navigation menu:
- Go to the Administration > Users page.
- In the Users Page:
- Select the value supplied in User Name from the list of users.
- Click View User.
- In the User Administration page in the Roles and Effective Permissions section:
- Click Edit Roles.
- In the Assign Roles page in the Role Management > Grant Roles section:
- Click Edit.
- In the Edit Grant Roles dialog window:
- Select the role named Discover Read Only User.
- Click Save.
- In the Assign Roles page:
- Click Show Preview to Continue.
- Click Save.
- In the Notice dialog window:
- Click Continue.
- The User Administration page should look like this:
- Perform the steps in Verifying Permissions
Verifying Permissions
- Log in to the value supplied in Hostname or IP Address with the values supplied in User Name and Password.
- In the navigation menu:
- Go to the Discover page.
- In the Discover menu of the Discover page:
- Go to the Interfaces > All page.
Field Mappings
The following tables show how values are mapped to fields in Axonius.
Aggregated Fields
Source | Destination |
---|---|
asset: computerid | UUID |
asset: computerid, asset: macaddress | ID |
asset: createdAt | First Seen |
asset: ipaddress | Network Interfaces |
asset: lastDiscoveredAt | Last Seen |
asset: os, asset: osgeneration | OS Guess |
asset: ports | Open Ports |
asset: tags | Adapter Tags |
Adapter Specific Fields
Source | Destination |
---|---|
asset: cloudTags | Tags Cloud |
asset: computerid | Computer ID |
asset: createdAt | Created At |
asset: hostname | Discover Hostname |
asset: ignored | Is Ignored |
asset: instanceId | Instance ID |
asset: instanceState | Instance State |
asset: instanceType | Instance Type |
asset: ismanaged | Is Managed |
asset: lastDiscoveredAt | Last Discovered At |
asset: lastManagedAt | Last Managed At |
asset: launchTime | Launch Time |
asset: locations | Locations |
asset: macorganization | MAC Organization |
asset: method | Methods Used |
asset: natipaddress | NAT IP Address |
asset: networkId | Network ID |
asset: os | OS Scanned |
asset: osgeneration | OS Generation |
asset: ownerId | Owner ID |
asset: profile | Profile |
asset: provide | Provider |
asset: tags | Tags Discover |
asset: unmanageable | Is Unmanageable |
asset: updatedAt | Updated At |
asset: zone | Zone |
Discover Report Name | Report Source |
Tanium Server | Tanium Server Name, Tanium Server Version, Module Version |
Version Matrix
This adapter has only been tested with the versions marked as supported, but may work with other versions. Please contact Axonius Support if you have a version that is not listed and it is not functioning as expected.
Version | Supported | Notes |
---|---|---|
Tanium versions prior to 7.3.314.3424 | No | This adapter utilizes the REST API, which was added in Tanium 7.3.314.3424 |
Tanium 7.3.314.3424 | Yes | |
Tanium 7.3.314.3668 | Yes | |
Tanium 7.3.314.4147 | Yes | |
Tanium 7.3.314.4250 | Yes |
Discover Module Versions
Modules within Tanium have their own version which is separate from the platform version.
Version | Supported | Notes |
---|---|---|
Discover Module 2.11.1.18 | Yes | |
Discover Module 3.1.0.0185 | Yes | |
Discover Module 3.1.2.0007 | Yes |