2.4 Creating Saved Questions: Reissue Intervals, Merge and Drill-Down Flags, and RBAC
Key Takeaways
- A saved question is stored on the Tanium Server as a configuration object carrying its reissue interval, access permissions, merge and drill-down settings, and any associated packages.
- Selecting 'Reissue this question every' with a number and a unit of Minutes, Hours or Days makes the server issue the question immediately on save and then reissue it exactly on that interval regardless of daylight saving changes.
- Reissuing lets a saved question collect results from endpoints that were offline at first issue, and the Tanium Server stores responses for seven days by default and shows them as Recent results.
- A saved question appears on another operator's Merge dialog only if the setting that displays it in the list of questions available to merge is enabled, and the same pattern applies to drill-down.
- A saved question, dashboard or category can belong to only one content set, and Visibility can be restricted so that only the owner and administrators see the object.
2.4 Creating Saved Questions: Reissue Intervals, Merge and Drill-Down Flags, and RBAC
Quick overview: A saved question is a question stored on the Tanium Server as a configuration object, complete with its reissue interval and access permissions. Saving a question means you never rebuild it, that it can reissue on a schedule and therefore pick up endpoints that were offline when you first asked, and that it can be offered to other operators as a merge or drill-down target. Blueprint objective AQ-3 asks you to determine the appropriate method to create a saved question — which is as much about choosing the right settings as about clicking Save.
1. What a saved question actually is
Saved questions expedite collecting information from endpoints because you can reissue them without reconstructing them in the Ask a Question field or the Question Builder. Beyond convenience, a saved question carries settings that a one-off question cannot:
- a reissue interval, so the server asks it again on a schedule;
- access permissions, through the content set it belongs to;
- settings that facilitate merge and drill-down operations when analysing results;
- an association with specific packages, to make deploying an action from its results easier.
Two ways they come into existence
| Origin | How it appears |
|---|---|
| Predefined | Tanium solutions you import provide their own saved questions. On Administration > Content > Saved Questions, the User Name column shows the Tanium solution as the owner |
| Custom | You issue a dynamic question through the Ask a Question field or the Question Builder and then save it |
[!IMPORTANT] Do not edit the predefined saved questions that Tanium solutions provide. A solution upgrade can overwrite or conflict with your edits. If a Tanium-provided question is nearly right, clone it and edit the clone.
2. Choosing a reissue interval
When you create a saved question you may select Reissue this question every and specify a number and a unit — Minutes, Hours or Days.
The behaviour is precise and worth knowing exactly:
- The Tanium Server issues the question immediately after you save the configuration, and clients that are online at that moment answer.
- The Server then reissues it in the background at the specified interval. Save at 9:00 a.m. with an eight-hour interval and it reissues at 5:00 p.m., 1:00 a.m., 9:00 a.m., and so on.
- It reissues exactly every interval, regardless of daylight saving time changes.
- You can confirm it is behaving by checking question history.
Why an interval buys you coverage
A single question only reaches endpoints that are online at that instant. A reissuing saved question keeps asking, so it collects results in the future from endpoints that are not yet online. A laptop that is shut at 9:00 a.m. is very likely to be running at least once during an eight-hour cycle.
By default the Tanium Server stores responses for seven days, and the Question Results page shows them as Recent results for endpoints that were offline when the Server issued the question. That is what lets a saved question represent a fleet rather than a snapshot of whoever happened to be awake.
Choosing the number
There is no universal correct interval, but there is a governing constraint: a shorter interval means more sensor executions on every endpoint. Tanium's own best-practice guidance is explicit that a lower Max Sensor Age or Maximum Data Age increases endpoint CPU usage, and that you should not lower the defaults for sensors used in saved questions that periodically reissue, in questions used to deploy actions, or in questions that define membership in computer management groups and filter groups.
| Data you are collecting | Sensible interval shape |
|---|---|
| Slowly changing inventory — chassis type, serial number, installed memory | Hours to days |
| Operational state — service status, disk space, patch state | Hours |
| Investigation-driven or expensive forensic sensors | No reissue at all — run it manually when needed |
Leaving reissue off is a legitimate and often correct choice. A saved question with no reissue interval is still valuable: it standardises the question text so every operator asks it the same way.
3. Settings that shape how others use your question
Merge and drill-down availability
Two settings control whether your saved question is offered to other operators in the results grid:
- Display this question in the list of questions that are available to merge — required for it to appear on the Merge dialog's Saved Questions tab.
- Display this question in the list of questions that are available for drilling down — controls the default drill-down list. Operators can still tick Show all questions to reach questions without the flag.
If a colleague says "your question does not show up when I click Merge", this flag is almost always the answer — after checking that their question is non-counting.
Visibility
The Visibility setting decides who can see the object at all:
| Visibility option | Effect |
|---|---|
| According to RBAC | Users need Saved Question read permission on the content set the question belongs to |
| Only the Owner and Admins can see this object | Only the question owner and users with the Administrator reserved role can see it |
By default the creator is the owner, and ownership can be transferred.
Content set
Every saved question belongs to a content set, and a saved question, dashboard or category can belong to only one content set. Assigning a question to a dashboard does not realign content-set permissions to account for the dependency, so a dashboard can end up visible to someone who cannot see one of its questions. Keep related content in the same content set unless you have a reason not to.
Associated packages
A saved question can be associated with specific packages, so that when an operator selects results the relevant remediation package is immediately offered. This is how a "find the problem" question and a "fix the problem" package become a single workflow.
4. Where saved questions are managed
| Task | Where |
|---|---|
| View, issue, create and edit saved questions | Interact Overview page |
| Move a question between content sets | Interact Overview page |
| Define categories and dashboards, and assign questions to them | Interact Overview page |
| See ownership and the full object list | Administration > Content > Saved Questions |
| Confirm a reissue actually happened | Question history |
Note one visibility quirk that surprises operators: which users can see the reissue interval for a saved question depends on the computer groups assigned to those users.
5. When Reporting is the better place to look
Tanium's own guidance: if a question uses sensors that are registered with Tanium Data Service, Tanium Reporting has advantages over Interact for viewing the results. Reporting works from stored data, so it can show endpoints that are offline right now and can build reusable reports and dashboards on top of the same sensors. Chapter 6 covers Reporting.
A useful rule of thumb for the exam and for real work:
Need ground truth right now, from endpoints that are online? -> Interact question
Need a repeatable question other operators will re-run? -> Saved question
Need fleet coverage including offline endpoints, over time? -> TDS-registered sensors + Reporting
6. A worked example
Requirement: the security team wants a standing view of endpoints where the Windows Firewall service is not running, refreshed a few times per shift, usable by tier-1 analysts, and ready to deploy the remediation package from.
- Build it in Interact and confirm the result set is sane.
- Save it with a clear name that says what it finds.
- Set Reissue this question every 4 Hours — frequent enough to catch drift within a shift, infrequent enough not to hammer endpoints.
- Put it in the content set the tier-1 analyst role can read, and leave Visibility at According to RBAC.
- Enable available for drilling down so analysts can pivot from a result row to endpoint identity.
- Associate the remediation package, so the fix is one click from the finding.
- Check question history the next day to confirm it reissued on schedule.
An operator saves a question at 9:00 a.m. and sets it to reissue every eight hours. What does the Tanium Server do?
Why does a reissuing saved question give better fleet coverage than a single one-off question?
A colleague reports that your non-counting saved question does not appear when they click Merge in the Question Results grid. What should you check first?
A Tanium solution provides a predefined saved question that is close to what your team needs. What is the recommended approach?