5.1 Console Layout, the Main Menu and Where Things Live
Key Takeaways
- The Main menu separates Modules, which are the imported solution workbenches, from Administration, which holds the platform objects those modules are built on.
- Computer groups are managed at Administration > Permissions > Computer Groups, filter groups at Administration > Permissions > Filter Groups, and client connectivity at Administration > Configuration > Client Status.
- Scheduled Actions, Action History and All Pending Approvals all live under Administration > Actions, and Client Status and Packages both double as action initiation points.
- A persona determines which endpoints a session can see and which content and approval permissions apply, so an unexpected result set should prompt a persona check first.
- The Interact Overview page is where saved questions are viewed, created, moved between content sets and organised into categories and dashboards.
5.1 Console Layout, the Main Menu and Where Things Live
Quick overview: Blueprint objective NAV-3 asks you to determine the appropriate area to gather task-specific information. That is a navigation question, and it is answered by knowing the console's shape: Modules for the solution workbenches, Administration for the platform objects that govern them, Interact for asking, and the persona control for the scope you are operating under. This section is the map; the rest of chapter 5 walks the territory.
1. The shape of the console
The Tanium Console is a web interface organised around a Main menu on the left, which expands into two broad groups plus the platform's own settings:
| Group | What lives there |
|---|---|
| Modules | The solution workbenches — Interact, Reporting, Deploy, Patch, Asset, Comply, Threat Response, Discover, Reveal, Enforce, Performance and the rest of the imported solutions |
| Administration | The platform objects the modules are built on — content, actions, permissions and configuration |
The Tanium Home page collects favorite Interact categories, dashboards and saved questions, which is how an operator makes a fifteen-module console feel like a five-item one.
2. The Administration menu is the map that matters
Almost every "where do I go to…?" question in this domain resolves to a path under Administration. These are the ones an operator uses constantly, and they are worth memorising as paths rather than as concepts.
| Task | Path |
|---|---|
| Manage computer groups that are management groups (or both types) | Administration > Permissions > Computer Groups |
| Manage groups that function exclusively as filter groups | Administration > Permissions > Filter Groups |
| Manage roles and RBAC | Administration > Permissions |
| Review and manage packages | Administration > Content > Packages |
| See all saved questions and their owners | Administration > Content > Saved Questions |
| Manage recurring actions and actions with a future start | Administration > Actions > Scheduled Actions |
| Audit what has already been deployed | Administration > Actions > Action History |
| See everything awaiting approval (Admin reserved role) | Administration > Actions > All Pending Approvals |
| Check client connectivity and registration | Administration > Configuration > Client Status |
[!TIP] Two of these double as action initiation points: you can select up to 100 clients on Client Status and click Deploy Action, and you can select a package on Content > Packages and click Deploy Action. Knowing that turns a navigation question into a one-step answer.
3. Interact: the Overview page and the question field
Interact is where questions are asked and where saved questions are curated.
| Interact surface | Purpose |
|---|---|
| Question field (Ask a Question / Explore Data) | Type a free-form question, or open the Question Builder for explicit construction |
| Question Results page | The grid: filter, sort, select rows, drill down, merge, copy, export, deploy actions |
| Interact Overview page | View, issue, create and edit saved questions; move questions between content sets; define categories and dashboards; manage favorites |
Categories and dashboards are the organising layer on top of saved questions, and they are how a team publishes a curated set of questions to colleagues who should not have to invent question text themselves.
4. Personas: the scope you are currently operating under
A persona bundles the roles and computer group assignments a user operates with for a session. It exists because one human often holds several operational identities — a desktop-support scope during the day, an incident-response scope when an alert fires — and mixing them is how accidents happen.
What a persona changes:
- Which endpoints you see. Question results come only from endpoints in computer management groups assigned to the user or persona selected for the current session.
- What content you can use. Roles assigned to the persona determine which sensors, packages and saved questions are available.
- What you can approve or bypass.
Approve ActionandBypass Action Approvalroles can be assigned to personas as well as to users and user groups. - What you can see about saved questions. Even the visibility of a saved question's reissue interval depends on the computer groups assigned.
[!IMPORTANT] When results do not look right, check the active persona before you check anything else. "The question is broken" and "I am in the wrong persona" produce identical symptoms, and the second is far more common.
5. A navigation decision table
This is the compressed answer to most NAV-3 scenario items.
| The question you are being asked | Where you go |
|---|---|
| "What is true on endpoints right now?" | Interact — ask a question |
| "What has this module been doing over time?" | That module's workbench (see 5.2 and 5.3) |
| "What does the fleet look like, including offline endpoints?" | Reporting (see chapter 6) |
| "Did my change land, and on which endpoints?" | Administration > Actions > Action History |
| "Is this endpoint even talking to Tanium?" | Administration > Configuration > Client Status |
| "I need a live look inside one endpoint" | Direct Connect (see 5.5) |
| "Who can see or do this?" | Administration > Permissions — roles, computer groups, filter groups |
| "Why is this action stuck?" | Administration > Actions > All Pending Approvals, then Action History |
| "I need this outside Tanium" | Export from the results grid, or Connect (see chapter 6) |
6. Reading the results grid
The Question Results page is where an operator spends most of their console time, so its controls are worth naming explicitly:
- Progress indication — results stream in as endpoints answer, so a grid that is still filling is normal, and a grid that stops short of the full population usually means endpoints are offline rather than that something failed.
- Row selection — click the first checkbox, hold Shift, click the last, to select a consecutive block for drilling down, copying, exporting or deploying actions.
- Copy — copies selected rows to the clipboard, with each row as a comma-separated value string; Copy Cell Value copies one cell.
- Export — writes the grid to CSV (chapter 6).
- Merge and Drill Down — covered in sections 3.3 and 3.2.
- Copy to Question Builder — takes the current question into the builder for explicit refinement.
- Deploy Action — up to 100 selected rows.
7. Where new capability comes from
Modules are imported solutions, not fixed furniture. That has two consequences an operator meets quickly:
- The menu differs between environments. A module you used at a previous employer may simply not be imported here. When an exam item names a module, it is telling you which workbench the scenario assumes.
- Solutions bring their own content. Importing a solution adds its predefined saved questions, packages, sensors and reports — which is why Administration > Content > Saved Questions shows Tanium solutions as owners in the User Name column, and why Tanium advises cloning rather than editing that content.
An operator needs to confirm whether a set of endpoints is registering with the Tanium Server at all. Which console area is designed for this?
Two operators run the same question and one sees far fewer endpoints. Before investigating the question itself, what should be checked?
Where does an operator go to audit which endpoints a deployed action actually reached and what status they reported?
Why does the set of modules visible in the Main menu differ between two Tanium environments?