Overview & Purpose
Tanium Investigate bridges the gap between detecting an issue and resolving it. Launched Q3 2023, it reduces Mean Time to Investigate (MTTI) and Mean Time to Remediate (MTTR) by consolidating endpoint data, collaboration, and remediation into one workspace.
The 5 Pillars of Investigate
If Tanium Performance is the smoke detector, Tanium Investigate is the firefighter's toolkit -- thermal camera, hose, radio, and incident report all in one.
The Problem: Swivel-Chair Troubleshooting
Without Investigate, a single "my laptop is slow" ticket sends a tech through 5+ tools and 45 minutes of tab-switching.
Ticket Arrives
Read the help desk ticket description
Lookup Machine
Open SCCM / endpoint tool to find the device
Check Monitoring
Switch to a separate monitoring dashboard
Remote In
Use a separate remote-access tool
Manual Checks
Event logs, Task Manager, installed apps
Ask a Colleague
Message on Teams: "Have you seen this before?"
Investigate collapses all 6 steps into one console.
Performance vs. Investigate
| Aspect | Tanium Performance | Tanium Investigate |
|---|---|---|
| Focus | Monitoring & health scoring | Active troubleshooting & resolution |
| Primary Use | Detecting degradation proactively | Diagnosing root cause of known issues |
| View | Fleet-wide dashboards & trends | Single endpoint deep-dive & workspaces |
| Data | Aggregated health scores & metrics | Granular process-level & event-level data |
| Actions | Alerting, reporting, fleet remediation | Remote mgmt, file download, process control |
Tandem Workflow
Performance Detects
Health scores drop on 15 Sales endpoints
Performance Alerts
Threshold alert fires, IT Ops notified
Investigate Takes Over
Tech opens SEV on an affected machine
Investigate Diagnoses
CRM update causing a memory leak identified
Investigate Remediates
Kill process + deploy rollback from workspace
Key Terminology
Scenario: Map the Right Tool
For each situation, decide whether you would use Tanium Performance, Tanium Investigate, or both working together.
A. You need to see fleet-wide boot time trends across all departments this month.
B. A user reports Outlook keeps freezing. You need to see which process is consuming memory on their machine.
C. Health scores drop for 30 endpoints in Accounting. You need to find out why and fix it.
Who Uses Investigate?
Match each persona to their primary use case:
✍ Knowledge Check
1. What two metrics is Tanium Investigate specifically designed to reduce?
2. Which of the following is NOT one of the five pillars of Tanium Investigate?
3. How do Tanium Performance and Tanium Investigate work together?
DEX Specialization Training © 2026