Tanium Interact is the cornerstone of the Tanium Autonomous IT Platform. Built on top of our proprietary Linear Chain Architecture, it enables users to ask questions and gather live data from endpoints with the Tanium client installed, in real time, from almost anywhere within the Tanium console.
The platform's broader capabilities, including modules like Tanium Patch and Deploy, are all built on this same foundation of asking questions through sensors. Understanding how to use Interact effectively is, in practical terms, understanding how to get the most out of Tanium itself.
Tom covers the full spectrum of Interact's capabilities: how sensors work and how to combine them into precise questions, how to use the Question Builder to build complex AND/OR logic without memorizing syntax, how Tanium Data Service (TDS) caching makes data available for online and offline endpoints for up to 30 days, and how saved questions enable consistent recurring data collection. He also walks through the difference between Drill Down and Merge, explains counting questions versus granular per-endpoint results, and demonstrates the AI-powered Tanium Ask Agent.
Whether you're new to Tanium or looking to sharpen your querying skills, this episode covers the practical mechanics that separate basic usage from expert-level visibility, including regex filters, sensor browsing, and how to generate a complete question from plain-language input using the Ask Agent. Watch the full episode below.
Key takeaways
- Interact as the platform foundation: Interact is built on top of Tanium's Linear Chain Architecture and serves as the mechanism through which users ask questions, send packages, and gather information from any endpoint with the Tanium client, making it the cornerstone of everything built on the Tanium platform.
- Sensors are the building blocks: Questions are built from single or multiple sensors, with pre-built sensors available for Windows, Linux, and other supported operating systems. Sensors are fully customizable, meaning users can write their own scripts to gather specific information and build them into new sensors for use in questions.
“What we're doing here is we're asking questions based on all the sensors available to us. And we can do that from almost anywhere within the console.”Tanium Senior Enterprise Engineer Tom Dowdeswell
- Question Builder for complex queries: The Question Builder provides a visual interface for constructing questions with a top section (what data you want back) and a bottom section (from what endpoints), supporting AND/OR logic groups, row filters, and regex matching via the "matches" and "does not match" filter options, making it easier to build precise, multi-condition queries without memorizing question syntax.
- TDS caching for offline endpoints: When a sensor is registered with TDS, data can be continuously collected and stored for online and offline endpoints for up to about 30 days, depending on configuration. Switching from "Current" to "Cache" in the results view surfaces this stored data, which can significantly increase the number of endpoints returned, for example, from 45 to 123 results in the episode's demonstration.
- Saved questions for recurring data collection: Saved questions allow users to store complex, filtered queries and reissue them to endpoints on a schedule, typically every couple of hours, enabling consistent data collection without rebuilding queries each time. Once saved, questions surface three states of data: Current, Recent, and Cached.
- Drill Down versus Merge: Drill Down allows users to select a specific result row and ask additional questions scoped only to the endpoints that returned that result, effectively adding a filter based on the original selection. Merge combines questions together so that data from multiple sensors appears side by side in a single result set, for example, combining installed applications with computer name and operating system in one view.
“And I always say to my customers, "Start with that counting question." So start broad, go get lots of information, and we can see that from a counting perspective there's 74 of those, and then you want to start drilling down, start adding more of those filters.”Tanium Senior Enterprise Engineer Tom Dowdeswell
- Counting versus granular questions: Counting questions bucket results by response, showing how many endpoints returned each value, which provides a broad, high-level view. Adding unique data like computer name breaks results into one row per endpoint, producing a more granular per-device view that is useful for targeted investigation and remediation.
- Ask agent for AI-powered query building: The Tanium Ask Agent accepts plain-language input, such as "I would like to see all the installs of Zoom on Windows workstations," and builds the corresponding question, summarizes the results in a sentence, and provides options to view full results, copy, download, or save the question for future use.
“I think what was really good from this as well is that it kind of opens up the Tanium console to people that maybe aren't as used to it, aren't as technical, aren't as hands-on with it. They can just ask that simple question without trying to learn all the question syntax, where the filter should be, the left, the right, the top, the bottom, how you wanna look at that filtering. They just ask it, and it's gonna build it for you.”Tanium Senior Enterprise Engineer Tom Dowdeswell
Additional resources
- How Tanium Ask uses AI to translate natural-language queries into endpoint questions: Explore how Tanium Ask converts plain-language input into structured queries, enabling users to quickly retrieve real-time endpoint data across their environment.
- Exploring, building, and refining questions in Tanium Interact: Step-by-step documentation covering how to issue free-form and structured questions, use the Question Builder to select sensors and apply filters, and work with results to investigate and take action across endpoints.
- Getting started with the Tanium Ask AI agent for endpoint queries: Technical documentation on how to use the Tanium Ask Agent to submit plain-language queries, review AI-generated question syntax, interpret summarized results, and copy or save questions for ongoing use.
- How Tanium AI uses real-time intelligence to deliver safe, contextual insights and actions: Learn how Tanium AI applies real-time endpoint data to generate recommendations, surface key impacts, and enable secure, governed actions across IT and security workflows.
