6.2 Creating Reusable Reports with Tanium Reporting
Key Takeaways
- Tanium Reporting explores real-time visualisations of endpoint data, creates custom reports and charts, and exports data to share with stakeholders, and it has replaced the deprecated Trends module.
- The Source Data panel in Explore Data and report editing lists registered sensors, so a missing sensor means it is not registered with Tanium Data Service rather than a Reporting fault.
- Module sources can supply dashboard charts but cannot be created or edited and cannot be used on the Explore Data page, in reports, or in sensor details panels.
- Reporting runs a 24-hour collection cycle for report data, which does not apply to module sources whose push intervals vary by solution, and a new dashboard chart starts collecting only when created.
- Computer group filters require RBAC permissions on the groups to appear in the dropdown and do not apply to dashboard charts based on module sources.
6.2 Creating Reusable Reports with Tanium Reporting
Quick overview: Blueprint objective RPT-2 asks you to create reusable reports, and objective RQ-4 asks you to generate a report to identify computers sharing a common characteristic. Tanium Reporting is the current module for both: use it to explore real-time visualisations of endpoint data, create custom reports and charts from that data, and export the results to share with stakeholders. Reporting has replaced Trends, which is deprecated.
1. Why a report, not an export
A CSV answers a question once. A report answers it every time anyone opens it, for everyone permitted to see it. The difference matters as soon as more than one person needs the answer, or the same person needs it more than once.
| Export | Report | |
|---|---|---|
| Freshness | Frozen at export time | Refreshed by the module's collection cycle |
| Reuse | Re-run the question, re-export | Open it |
| Sharing | Send a file | Grant access |
| Governance | Leaves Tanium's access model behind | Stays inside RBAC |
| Trend | None — a snapshot | History accumulates |
Tanium is explicit about one case: if a question uses sensors that are registered with Tanium Data Service, Reporting has advantages over Interact for viewing the results — chiefly that stored data represents endpoints that are offline at the moment you look.
2. What Reporting is made of
| Object | What it is |
|---|---|
| Data sources | The information you build views from. In Explore Data and when editing reports, the Source Data panel lists all the registered sensors you can select |
| Module sources | Data that a Tanium solution provides. You can use module sources as the data source for dashboard charts, but you cannot create or edit them, and they cannot be used on the Explore Data page, in reports, or in sensor details panels |
| Explore Data page | Creates a view of endpoint data in grid format and configures a chart to visualise it |
| Reports | Saved, reusable views with their own charts |
| Dashboards | A collection of chart, action and text panels that visualise data from one or more reports, alert users to events, and let you deploy actions based on those events |
| Endpoint Details page | Per-endpoint detail, including sensor details panels and, where those modules are present, Deploy's Software Package Applicability and Patch's OS Patch Applicability and Maintenance Windows panels |
[!IMPORTANT] The Source Data panel lists registered sensors. If the sensor you need is not there, it is not registered with Tanium Data Service — that is the fix, not a Reporting problem. Register the sensor and it becomes available.
3. Collection cadence
Reporting runs a 24-hour collection cycle for report data. That cycle does not apply to module sources: the intervals at which Tanium solutions push updated module source data to Reporting vary by solution.
Two consequences for an operator:
- A newly created dashboard chart starts empty. Reporting begins collecting data for a dashboard chart only when the dashboard is created; it does not retroactively populate history.
- Do not read a Reporting figure as "right now". For current state, ask a question in Interact. For fleet coverage over time, read Reporting — and know which of the two you are quoting.
4. Tanium-managed content
Reporting ships with predefined content you should look at before building your own.
- Tanium-managed reports. Go to Data > Reports and filter by Author for the Tanium Managed options — for example
Tanium Managed - Patchshows the reports Tanium Patch provides.ADI - Basic Inventoryis a Tanium-managed report showing basic platform details about the endpoints in your environment where the Tanium Client is installed. - Tanium-managed dashboards. These address scenarios common to many environments, and include emerging issue dashboards openable from the Reporting workbench or from Tanium Guardian notifications. The content-only solution Tanium Emerging Issues Content carries the content for Tanium-managed dashboards, reports, sensors and packages.
The same principle applies as with saved questions: start from the Tanium-managed report, and clone rather than modify when it is nearly right.
5. Identifying computers that share a common characteristic
This is objective RQ-4, and Reporting is the durable way to satisfy it.
| Step | What you do |
|---|---|
| 1 | Confirm the sensor that expresses the characteristic is registered with TDS, so it appears in the Source Data panel |
| 2 | On Explore Data, select the sensor and build a grid view of the endpoints |
| 3 | Filter to the characteristic — a version, a state, a custom tag |
| 4 | Configure a chart to visualise the distribution |
| 5 | Save it as a report so colleagues re-open rather than rebuild it |
| 6 | Add the report to a dashboard if it belongs alongside related views |
| 7 | Export or schedule delivery where an audience lives outside Tanium (section 6.4) |
Computer group filters in Reporting
Reporting supports computer group filters, with two rules worth carrying:
- You require RBAC permissions for computer management groups and filter groups to see them in the dropdown list.
- Computer group filters do not apply to dashboard charts that are based on module sources. A chart fed by a module source shows what that solution sends, and a group filter will not narrow it.
6. Deploying an action from a report
Reporting is not read-only. A dashboard can carry action panels, and you can deploy a predefined action — an adaptive, ring-based action with predefined settings — directly from a report or a dashboard in Tanium Reporting. If the predefined settings need adjusting, click Edit and configure the action settings to deploy a custom action instead.
This closes the loop that chapters 4 and 6 describe from opposite ends: the report identifies the population, and the recommended action remediates it, without leaving the reporting surface.
7. Choosing between Interact, a saved question and a report
"Is this true right now?" -> Interact question
"Ask this the same way every time" -> saved question
"Show the whole fleet, including offline" -> report on registered sensors
"Show it to leadership, repeatedly" -> report on a dashboard
"Send it somewhere outside Tanium on a schedule" -> Connect (section 6.4)
The mistake to avoid is building the middle two out of the first one by hand — running a question every Monday and pasting it into a slide deck is a report that has not been created yet.
An operator opens Explore Data in Tanium Reporting and cannot find the sensor they need in the Source Data panel. What is the correct diagnosis?
A newly created dashboard chart shows no historical data even though the underlying report has existed for months. Why?
Which statement about module sources in Tanium Reporting is correct?
A team runs the same Interact question every Monday and pastes the result into a slide deck. What does the Report Generation and Data Export domain suggest instead?