Investigation Workspace
The Investigation Workspace is a shared virtual war room where teams collect endpoints, data, findings, and remediation actions for a single incident. It replaces scattered browser tabs, Teams messages, and personal notes with one persistent, collaborative record.
Investigation Workflow
Simulated: Investigation Workspace
| Endpoint | User | Department | Health | CRM Version | Status |
|---|---|---|---|---|---|
| CAEI778766 | jsmith | Accounting | 38 | 4.2.0-beta | Affected |
| CAEI782014 | mgarcia | Claims | 42 | 4.2.0-beta | Affected |
| CAEI779301 | tchen | Marketing | 35 | 4.2.0-beta | Affected |
| CAEI780455 | kwilson | Accounting | 78 | 4.1.2 | Healthy |
| CAEI781208 | rpatel | Claims | 81 | 4.1.2 | Healthy |
3 Ways to Create an Investigation
Workspace Visualizations
Investigation Lifecycle
New
Investigation created, endpoints being added
In Progress
Active data collection, analysis, annotation
Pending
Waiting for additional data or a change window
Resolved
Root cause found, remediation applied
Closed
Documentation complete, searchable for future reference
Start documenting from the very first step. Real-time annotations ensure no finding is lost, make handoffs seamless, and produce a much more accurate post-incident record than reconstructing from memory.
Scenario: What Would You Do?
Reported by: Maria Garcia, Claims Department
Subject: "Laptop extremely slow since this morning"
Details: Applications take forever to open, Outlook keeps freezing. Restarted twice -- no improvement. Colleague sitting next to her says her laptop is fine.
What is your first step?
Maria restarted twice and the issue persists. What does this tell you?
Maria's colleague is unaffected. What comparison would be most valuable?
✍ Knowledge Check
1. What is the main advantage of an Investigation Workspace over investigating endpoints individually?
2. Which is a valid way to create a new investigation?
3. What happens to workspace data after the investigation is resolved?
🏆 Progress Checkpoint — Lessons 1-4
You have completed the first half of Module 2. Answer all 5 questions to test your understanding before moving forward.
1. What are the five pillars of Tanium Investigate?
2. What data source does the SEV use when an endpoint is offline?
3. Which data type requires a live query and cannot be reliably obtained from cache?
4. What is the primary purpose of annotations in an Investigation Workspace?
5. In the investigation workflow, what comes immediately after identifying the root cause?
DEX Specialization Training © 2026