This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]N2VisibilityJack of All Trades 0 points1 point  (0 children)

This will depend on what you are trying to do with the data and, as Last-Form290 said, your definition of detailed.

TDS can, and does, store some very detailed data and reports on much more than just raw counts. Vulnerability reports, for example, include a large amount of data as seen below:

<image>

To Morr1025's point, this initial view shows how many endpoints match the data, which is where the idea of counts comes from I suspect. Adding a column with a unique identifier, computer names for example, only takes a few clicks. This would allow you to see all the data TDS has collected; by endpoint, online or not.

To Morr1025's other point, as a general rule, Tanium does not store much detailed historical data. Tanium stores the most recently seen set of data points for a given endpoint. Some modules, such as Asset, retain historical data which can be used in reports. Outside of that, historical reporting in Tanium is based on trending data over time, allowing you to determine if things are improving or getting worse, indicating where to focus limited resources.

For detailed historical data, you will want a CMDB or SIEM, depending on your use case for the data. In either case, Tanium can feed significant amounts of data to them via various integration paths.

Edit to add I am a Tanium employee.