Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Tanium Connector Guide

Prev Next

Tanium's converged endpoint management platform identifies data locations, patches devices, and enforces critical security controls. The Balbix integration with Tanium Asset, Tanium Patch, and Tanium Comply ingests infrastructure assets, system information, software details, vulnerability data, and patch information for assets managed by Tanium.

Balbix uses AI to aggregate, normalize, and deduplicate the ingested data from Tanium, along with information from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their operational and business context.

Balbix’s AI models analyze this data to deliver insights such as:

  • Deployment gap analysis: Identify areas lacking security coverage.

  • Risk-based vulnerability prioritization: Provide detailed ranking and scoring of vulnerabilities based on risk.

  • Risk quantification: Assess risk at the asset, group, or enterprise level.

This comprehensive approach enables more informed and effective security decisions, allowing you to proactively manage risk across your organization.

Integration summary

This table provides a summary of the Balbix integration for the Tanium connector.

Integration type

Fetch: An inbound API integration used to retrieve assets and related information.

Types of assets fetched

Host devices, including servers, virtual machines, desktops, and laptops.

Types of data fetched

Asset names, hardware information, CPU information, interface information (MAC address, IP address), OS information, BIOS information, system information, software information, vulnerability information, control assessment information, and patch information including patch status.

Prerequisites

To set up the Balbix connector, you must first create Tanium API credentials with the necessary permissions. These credentials are required to complete the configuration process.

Steps to create Tanium API credentials:

  1. Create a Tanium user account or persona.

  2. Create an API key.

Tanium User Account/Persona

You need a Tanium user account or persona with the appropriate roles to generate an API token.

Required roles:

  • Asset Report Reader

  • Asset API User

  • Comply Report Reviewer

  • Gateway User

Steps:

  1. Log in to Tanium with an admin role account.

  2. Create a new user account, edit an existing user account, or create a persona.

  3. Assign or verify the required roles for the user account or persona.

Generate an API Key

To generate an API key in Tanium:

  1. Log in to your Tanium using an account with the API Gateway User and Comply Report Reviewer roles.

  2. Go to Administration > Permissions > API Tokens.

  3. Click New API Token and configure the following:

    • Notes: Optionally, add a description of the token's purpose.

    • Expiration: Set the expiration interval in days (default is 7 days, maximum is 365 days).

    • Persona: Select the user account (default persona) or an alternative persona to bind the token. The default persona is the one used in your current Tanium Console session.

    • Trusted IP Addresses: Enter the external IP addresses of systems that will use this token to authenticate with Tanium Cloud. Use IPv4 format (e.g., 192.0.2.0/24), separating multiple entries with commas or new lines.

  4. Click Save to generate the API token.

    Note: Copy the API token and securely store it for use when configuring the Tanium connector in Balbix.

Set up your Tanium connector

After completing the prerequisites, follow these steps to configure your Balbix connector for Tanium.

Field Mapping

Imported Fields

Balbix Fields

computer_id

asset_id

computer_name

host_name

ci_patch_installation_state install_status

patch_status

ci_patch_installation_state kb_article

patch_number

bios_release_date

bios_release_date

bios_vendor

bios_vendor

bios_version

bios_version

chassis_type

chassis_type

cpu_core

count_cpu_cores

cpu_manufacturer

cpu_manufacturer

cpu_name

cpu_model_name

operating_system

os_name

os_version

os_kernel

ci_network_adapter ipv4_address

ip_address

ci_network_adapter mac_address

mac_address

ci_installed_application normalized_name

sw_product_name

ci_installed_application normalized_vendor

sw_product_vendor

ci_installed_application version

sw_product_version

API reference documentation

To learn more about the Tanium API, see the references listed below: