Document toolboxDocument toolbox

edr.tanium

Introduction

The tags beginning with edr.tanium identify events generated by the Tanium Core Platform.

Valid tags and data tables

The full tag must have 3 levels. The first two are fixed as edr.tanium. The third level identifies the type of events sent. 

Technology

Brand

Type

Technology

Brand

Type

edr

tanium

  • action_history

  • applicable_patches

  • asset_report

  • audit

  • basic_asset

  • client_status

  • detect

  • discover_lost

  • discover

  • events

  • installedapps

  • patch_list

  • question

  • threat_response

  • threats

These are the valid tags and corresponding data tables that will receive the parsers' data:

Tag

Data table

Tag

Data table

edr.tanium.action_history

edr.tanium.action_history

edr.tanium.applicable_patches

edr.tanium.applicable_patches

edr.tanium.asset_report

edr.tanium.asset_report

edr.tanium.audit

edr.tanium.audit

edr.tanium.basic_asset

edr.tanium.basic_asset

edr.tanium.client_status

edr.tanium.client_status

edr.tanium.detect

edr.tanium.detect

edr.tanium.discover_lost

edr.tanium.discover_lost

edr.tanium.discover

edr.tanium.discover

edr.tanium.events

edr.tanium.events

edr.tanium.installedapps

edr.tanium.installedapps

edr.tanium.installedapps.v2

edr.tanium.installedapps

edr.tanium.patch_list

edr.tanium.patch_list

edr.tanium.question

edr.tanium.question

edr.tanium.threat_response

edr.tanium.threat_response

edr.tanium.threats

edr.tanium.threats

Â