6.4 Scheduled Delivery and Exporting to External Systems with Tanium Connect

Key Takeaways

  • A Tanium Connect connection pairs a source such as a saved question, module source, report or dashboard with a destination, and can be run manually or on an enabled schedule.
  • Connect destinations include Email, File, HTTP, Socket Receiver, Splunk and SQL Server, and the available format options depend on the destination type selected.
  • Filters modify data from the source before it is sent, and the Columns section sets each field's Destination Label, Value Type and Customization for the receiving system.
  • Connections scheduled to run during an upgrade of Connect or of any solution configured as a connection source might be interrupted or fail, so delivery should be verified after upgrades.
  • Data delivered to an external destination leaves Tanium's content set and computer group access model, so connections should be scoped to the minimum the destination requires.
Last updated: August 2026

6.4 Scheduled Delivery and Exporting to External Systems with Tanium Connect

Quick overview: A manual export ends when the operator stops doing it. Tanium Connect is how Tanium data leaves the platform on a schedule, unattended, into the systems that consume it — a mailbox, a file share, an HTTP receiver, a SIEM, or a database. A connection pairs a source with a destination, optionally filters and shapes the columns in between, and optionally runs on a schedule.


1. What Connect is for

Connect captures accurate and complete endpoint data from Tanium and delivers it elsewhere. It answers the requirements that neither a CSV nor a dashboard can:

RequirementWhy export and dashboards fall short
"Our SIEM needs Tanium alerts"The SIEM cannot open a dashboard
"The CMDB must be refreshed nightly"Nobody will export a CSV at 02:00 every night
"Audit retention beyond the module's window"Module data ages out; the archive must live elsewhere
"Leadership wants it in their inbox"They will not sign in to read it

Tanium makes the retention case explicitly: if you need to retain audit logs or system notifications for longer periods than a module holds them, send the data to Tanium Connect.


2. The anatomy of a connection

   +----------+     +-----------+     +-----------+     +---------------+
   |  SOURCE  | --> |  FILTERS  | --> |  COLUMNS  | --> |  DESTINATION  |
   +----------+     +-----------+     +-----------+     +---------------+
        |                 |                 |                   |
   saved question,   narrow the data   choose fields,      Email, File, HTTP,
   module source,    before it is      set Destination     Socket Receiver,
   Reporting report  sent              Label, Value Type   Splunk, SQL Server
   or dashboard                        and Customization
                                  +-------------------+
                                  |     SCHEDULE      |
                                  |  Enable Schedule  |
                                  +-------------------+

Sources

SourceExample use
Saved questionPeriodically issue a saved question and send its results to an external server
Reporting dashboards and reportsDeliver the same view an internal audience sees on a dashboard
Module sourcesThreat Response events and alerts, Comply findings and assessments, the Direct Connect audit log, and others

Destinations

Connect destinations include Email, File, HTTP, Socket Receiver, Splunk and SQL Server. Which format options are available depends on the destination type you select.

Filters and columns

Filters modify the data coming from the source before it is sent — narrowing rows so the destination receives what it needs rather than everything. In the Columns section you select the available source items and configure each one's Destination Label, Value Type and Customization, which is how a Tanium column name becomes the field name the receiving system expects.

Schedule

A connection can be run manually with Run Now, or scheduled by selecting Enable Schedule and configuring the timing.

[!IMPORTANT] Connections scheduled to run during an upgrade of Connect — or of any Tanium solution configured as a connection source — might be interrupted or fail. Build maintenance windows into your connection schedules, and check the delivery after any upgrade.


3. Building and validating a connection

StepWhat you do
1Enter a Name and optional Description. The Log level defaults to Information
2Select the Source — the saved question, module source, report or dashboard
3Configure source-specific settings, such as a Batch Size for the number of rows returned at a time
4Select the Destination and its settings
5Configure Filters to narrow the data
6Configure Columns — labels, value types, customisation
7Click Run Now and confirm, then view the output in the destination you configured
8Enable and configure the Schedule

Step 7 is not optional in practice. A connection that has never been run has never been proven, and a scheduled connection that silently fails is worse than no connection at all — the audience assumes no news is good news.


4. Choosing among the export routes

RequirementRoute
A few rows into a ticket right nowCopy from the results grid
One-off spreadsheet analysisExport to CSV (section 6.1)
A colleague who has Tanium access needs it repeatedlyA report or dashboard (section 6.2)
A system, a mailbox or an archive needs it on a scheduleConnect
Long-term retention beyond a module's windowConnect to a file, SQL Server or SIEM destination

[!TIP] The blueprint objective is determine the correct method to export required data for use outside of the application. The word method is doing real work: recognising when a manual export is the wrong answer is exactly what is being assessed. Ask who consumes it, how often, and what happens if nobody does it this week — those three answers select the method every time.


5. Governance considerations

  • Delivered data leaves Tanium's access model. Content sets, roles and computer management groups govern the console. A CSV on a file share or a table in SQL Server is governed by that system's controls instead. Scope the connection's filters and columns to the minimum the destination needs.
  • Note the scope. A connection sourced from a saved question inherits the visibility rules of the question. Record which computer groups the delivered data represents, because the file itself will not say.
  • Prefer filtering at the source. Sending everything and filtering downstream costs bandwidth, storage and, when the data is sensitive, risk.
  • Monitor delivery, not just configuration. Upgrades, credential expiry and destination changes all break connections silently. The connection's log level and the destination's own records are where you find out.
Loading diagram...
Selecting an export method by consumer and cadence
Test Your Knowledge

A security team needs Tanium alert data delivered continuously into their SIEM. Which approach fits, and what are the two main configuration choices?

A
B
C
D
Test Your Knowledge

Why does Tanium warn about connections that are scheduled to run during a solution upgrade?

A
B
C
D
Test Your Knowledge

In a Connect connection, what is the purpose of the Columns section?

A
B
C
D
Test Your Knowledge

What is the main governance consideration when configuring a Connect connection that delivers endpoint data to a file destination?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams