Tanium Attribute Reference
Focus
Focus
Device Security

Tanium Attribute Reference

Table of Contents

Tanium Attribute Reference

This reference lists the attributes that Device Security collects from Tanium, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Tanium, it imports endpoint management data to enrich the device inventory. The attributes in this reference cover device identification, hardware, OS, and vulnerability findings from Tanium-managed endpoints.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Device Attributes

Device Security collects device attributes from Tanium. The following table lists each Tanium attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tanium Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
domainName
tanium.domainName
AD Domain
Domain name
"Tanium"
—
Endpoint Protection Vendor
"tanium"
name
tanium.name
hostname
Name of the device
macAddress
tanium.macAddress
id; MAC Address
MAC address
ipAddress
tanium.ipAddress
IP Address
IP address
model
tanium.model
Model
Model of the device
os.platform
tanium.os.platform
OS Group
Platform
os.name
tanium.os.name
OS Name
Name of the device
os.windows.majorVersion
tanium.os.windows.majorVersion
OS Version
Major version
serialNumber
tanium.serialNumber
Serial Number
Serial number
installedApplications
—
third_party_learned_installed_software
Installed applications
networking.adapters
—
third_party_learned_network_interfaces
Adapters
entityType
tanium.entityType
user_defined_device_type
Entity type
manufacturer
tanium.manufacturer
Vendor
Manufacturer of the device
isWireless
tanium.isWireless
Wired - Wireless
Is wireless
chassisType
tanium.chassisType
—
Chassis type
computerID
tanium.computerID
—
Computer ID
disks.free
tanium.disks.free
—
Free
disks.usedPercentage
tanium.disks.usedPercentage
—
Used percentage
disks.usedSpace
tanium.disks.usedSpace
—
Used space
entityProviderName
tanium.entityProviderName
—
Entity provider name
isEncrypted
tanium.isEncrypted
—
Is encrypted
isEndpoint
tanium.isEndpoint
—
Is endpoint
isVirtual
tanium.isVirtual
—
Is virtual
lastLoggedInUser
tanium.lastLoggedInUser
—
Last logged in user
memory.ram
tanium.memory.ram
—
RAM
memory.total
tanium.memory.total
—
Total
os.windows.releaseId
tanium.os.windows.releaseId
—
Release ID
os.windows.type
tanium.os.windows.type
—
Type
primaryUser.country
tanium.primaryUser.country
—
Country
primaryUser.department
tanium.primaryUser.department
—
Department
primaryUser.email
tanium.primaryUser.email
—
Email
primaryUser.name
tanium.primaryUser.name
—
Name of the device
primaryUser.phoneNumber
tanium.primaryUser.phoneNumber
—
Phone number
processor.architecture
tanium.processor.architecture
—
Architecture
processor.cacheSize
tanium.processor.cacheSize
—
Cache size
processor.consumption
tanium.processor.consumption
—
Consumption
processor.cpu
tanium.processor.cpu
—
CPU
processor.family
tanium.processor.family
—
Family
processor.logicalProcessors
tanium.processor.logicalProcessors
—
Logical processors
processor.manufacturer
tanium.processor.manufacturer
—
Manufacturer of the device
systemUUID
tanium.systemUUID
—
System UUID

Vulnerability Attributes

Device Security collects vulnerability attributes from Tanium. The following table lists each Tanium attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tanium Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cveId
tanium.cveId
cve
Cve ID
cvssScore
tanium.cvssScore
cvss_base_score
Cvss score
summary
tanium.summary
Description
Summary
lastFound
tanium.lastFound
detected_time
Last found
macAddress
—
id
MAC address
ipAddress
—
IP Address
IP address
severityV3
tanium.severityV3
risk_level
Severity v3
cveYear
tanium.cveYear
—
CVE year
firstFound
tanium.firstFound
—
First found
* Only some attributes map to a Device Security Common Attribute.