Skip to main content
Tanium REST app icon

Tanium REST

This app supports investigative and generic actions on TaniumBuilt by Splunk LLC
soar product badge

Default Version 4.0.0

August 31, 2026

Compatibility

SOAR On-Prem, SOAR Cloud

Platform Version: 8.7, 8.6, 8.5, 8.4, 8.0, 7.2, 7.1, 7.0

Rating
0
(0)

Log in to rate this app

Support
Splunk Supported
Ranking

#12 in Endpoint

This app supports investigative and generic actions on Tanium

Supported actions

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration.
  • make request: Make a generic HTTP request to the Tanium REST API.
  • create group: Create a Tanium manual computer group from hostnames and IP addresses
  • delete group: Delete a Tanium manual computer group by ID
  • execute action: Execute an action on the Tanium server
  • find groups: Find Tanium manual computer groups matching hostnames or IP addresses
  • get question results: Return the results for an already asked question
  • list processes: List the running processes of the devices registered on the Tanium server
  • list questions: Retrieves either a history of the most recent questions or a list of saved questions
  • parse question: Parses the supplied text into a valid Tanium query string
  • run query: Run a search query on the devices registered on the Tanium server
  • terminate process: Kill a running process of the devices registered on the Tanium server. Note: This action is retained for compatibility; the same operation can be performed using execute action, and terminate process will be deprecated in a future release.