r/tanium

▲ 2 r/tanium

New Devices/ Software install

I'm curious how those of you who are not using Tanium Provision are handling software deployment for brand-new devices.

I'm trying to determine the fastest and most reliable way to get a core set of applications installed almost immediately after a device comes online. My concern with Deploy is that there can be some delay while modules, inventories, and software scans complete before the endpoint is evaluated and assigned the appropriate deployment.

I've also considered using Actions, but I'm concerned about larger installers, download times, and overall reliability if the action completes before the installation finishes.

The workflow I'm trying to achieve is something like:

  1. Tanium Client gets installed.
  2. Device checks into Tanium.
  3. Device receives a tag, group membership, or some other identifier.
  4. Required software begins installing immediately.
  5. Identifier removed

I understand that one option is to bake these applications into the image or use scripts during the imaging process. Unfortunately, due to our current imaging and device replacement processes, we can't reliably depend on updating or replacing the image whenever software requirements change. Because of that, I'm specifically interested in approaches that leverage Tanium after the endpoint has been deployed and comes online.

For those of you managing new device provisioning with Tanium:

  • Are you using Deploy, Actions, Connect, or something else?
  • How are you triggering software installations as soon as a device first checks in?
  • What kind of time-to-install are you seeing from first check-in to software being installed?
  • Have you found a reliable way to handle larger installers or software dependencies?
  • Any lessons learned or pitfalls to avoid?

I'm interested in hearing what has worked well in production environments, especially for getting critical tools installed as quickly as possible after the endpoint comes online.

reddit.com
u/Main_Lifeguard7155 — 2 days ago
▲ 4 r/tanium

Adicionar Tags dinâmicas com base no Departamento

Fala pessoal, tudo bem?

Talvez seja uma pergunta de novato, mas vamos lá...

Recebi a demanda de fazer com que a Tanium aplique Tags com base na informação de "Departament", informação essa que é populada no perfil da máquina em "Primary User"

https://preview.redd.it/mzox38b75x3h1.png?width=246&format=png&auto=webp&s=f8ac4e2b8341f28f1d20ec10ee1d94acfcb4b5e6

Essa informações são populadas quando rodamos o pacote "Collect Active Directory Info".

Ai a demanda é o seguinte, a máquina tem o Departamento = (Ex: Suporte), e conseguir adicionar uma tag que leia esse nome e já crie e aplique a Tag "Suporte" nesta máquina.

Acredito que não é uma demanda simples, talvez até tenha que ser feito via criação de sensor/package, mas se alguem já fez algo semalhante e poder me dar umas dicas!

OBS: Tentei entender o "Enhanced Tags" porém não evolui muito.

Obrigado.

reddit.com
u/Scary-Mountain8647 — 13 days ago