Skip to main content

Tanium Patch Troubleshooting Guide

https://help.tanium.com/bundle/ug_patch_cloud/page/patch/troubleshooting.html

This guide documents how to interpret Tanium Patch health using the following questions:

  • Patch – Coverage Status Details

  • Patch – Scan Age

  • Patch – Scan Errors

  • Patch – Is Process Running

  • Endpoint Configuration – Tools Status Details (Patch)

Screenshots provided determine the exact logic included below.


1. Patch – Coverage Status Details

This question returns three columns:

  • Status – high-level health for Patch on the endpoint

  • Detailwhy that status was assigned

  • Count – number of machines with that Status/Detail combination

Example output (like in your screenshot):

Status Detail Count
Optimal N/A 11
Unsupported CX Unsupported 5
Needs Attention Stale Scan Results 1

1.1 Status Values & What They Mean

Optimal
  • Meaning: Patch is fully functional on the endpoint.

  • Typical Detail: N/A (no specific issue; everything is fine)

  • What to look for:

    • The majority of your endpoints should be Optimal / N/A.

    • If a machine is Optimal, but you still see patch issues, move on to:

      • Patch – Scan Age

      • Patch – Scan Errors


⚠️ Needs Attention (Detail: Stale Scan Results)

  • Meaning: Patch is installed, but something is wrong that affects patchingits quality or freshness.

  • Common Detail values you’ll see:

    • Stale Scan Results – patch scan data is too old

    • (You may also see other detail strings like tools issues, failed scans, etc., depending on your environment.)

  • What to look for:

    • Use the Detail column to understand the next step:

      • Stale Scan Results → check Patch – Scan Age and Patch – Scan Errors

      • Tool-related text (if present) → check Endpoint Configuration – Tools Status Details (Patch)

    • Check Count to understand the impact:

      • 1–2 machines → one-off endpoint problem

      • Many machines → possible policy, content, or network issue

Typical remediation for “Needs Attention / Stale Scan Results”:

  1. Check Patch – Scan Age on those endpoints.

  2. If scan age is high, run Patch – Scan Errors to see why scans are failing.

  3. Confirm the Patch engine process is running.

  4. If tools look broken, run Endpoint Configuration – Tools Status Details (Patch) to verify.


🚫 Unsupported

  • Meaning: Tanium Patch cannot manage this endpoint for patching.

  • Example Detail:

    • CX Unsupported – the OS/platform is not supported by the Patch module (for example, a consumer/unsupported Windows SKU or an OS version outside the supported matrix).

  • What to look for:

    • Check details to confirm why it’s unsupported:

      • CX Unsupported Usually means this OS edition or version is out of scope for corporate patching via Tanium.

    • Use Count to see if this is:

      • A few test/edge devices → probably fine

      • A lot of production machines → you might have people running unsupported OS builds

Typical remediation for “Unsupported / CX Unsupported”:

  • Validate OS/SKU against your Tanium Patch-supported platform list.

  • For important machines:

    • Plan OS upgrade/rebuild to a supported edition.

  • For non-critical or lab devices:

    • Document that they are out of the Patch scope and handle manually or via another tool.


1.2 How to Use “Coverage Status Details” in Practice

  1. Run 

    Get Patch – Coverage Status Details from all machines
  2. Sort by Status, then Detail.

  3. Interpret:

    • Optimal / N/A → healthy population.

    • Needs Attention / Stale Scan Results (or other issues) → these are your fix-me targets.

    • Unsupported / CX Unsupported → out-of-scope OS/platforms; review and decide whether to remediate or exclude from compliance.

  4. Next Steps by Status:

    • For Needs Attention → drill into:

      • Patch – Scan Age

      • Patch – Scan Errors

      • Patch – Is Process Running

      • Endpoint Configuration – Tools Status Details

    • For Unsupported → validate OS and plan lifecycle/upgrade.


If you send similar screenshots for Scan Age / Scan Errors / Is Process Running / Tools Status, I can tune those sections to match your exact output format as well, so the wiki lines up 1:1 with what you see in the console.

You said:


ChatGPT said:

Perfect — now that I’ve seen the exact output format for all Patch sensors in your environment, here is a fully accurate, drop-in wiki page that matches:

  • How Coverage Status Details displays

  • How Scan Age displays

  • How Scan Errors displays

  • How Is Process Running displays

  • How Tools Status Details displays

Everything

below is aligned 1:1 with your screenshots.


Tanium Patch Troubleshooting Guide

(Accurate to Actual Console Output)

This guide documents how to interpret Tanium Patch health using the following questions:

  • Patch – Coverage Status Details

  • Patch – Scan Age

  • Patch – Scan Errors

  • Patch – Is Process Running

  • Endpoint Configuration – Tools Status Details (Patch)

Screenshots provided determine the exact logic included below.


1. Patch – Coverage Status Details

This question returns:

  • Status → overall Patch health state

  • Detail → specific reason for the status

  • Count → number of affected endpoints


Example Output (your screenshot)

StatusDetailCount
OptimalN/A11
UnsupportedCX Unsupported5
Needs AttentionStale Scan Results1

What Each Status Means

Optimal (Detail: N/A)

Meaning:
Patch is fully operational on these endpoints.

What to look for:

  • No further action required.

  • These endpoints have:

    • Working patch engine

    • Valid scan results

    • Supported OS

    • Tools installed correctly

Next Steps:
None — these machines are healthy.


🚫 Unsupported (Detail: CX Unsupported)

Meaning:
The OS or configuration is NOT supported by Tanium Patch.

What to look for:

  • Typically means:

    • Unsupported Windows edition (Home, Education, LTSC depending on version)

    • Unsupported Linux distribution/version

    • Unsupported OS build

Remediation:

  • Upgrade OS to a supported version

  • If machines are intentionally unsupported (lab, personal, test):

    • Exclude them from compliance reports


⚠️ Needs Attention (Detail: Stale Scan Results)

Meaning:
Patch tools are installed but the last scan is too old.
These endpoints are failing to update patch inventory.

What to look for next:
Run these questions in order:

  1. Patch – Scan Age

  2. Patch – Scan Errors

  3. Patch – Is Process Running

  4. Tools Status Details (to confirm versions and installation)

Common Remediation:

  • Restart Patch service

  • Restart Tanium Client

  • Redeploy Patch tools

  • Fix scan errors (often WMI or catalog issues)


2. Patch – Is Process Running

This question returns two values:

Patch – Is Process Running from all machines

 

  • Yes → Patch engine process is running

  • [no results] → Patch engine NOT running or tools missing

Example Output

Patch – Is Process Running Count
Yes 12
[no results] 5

What Each Result Means

✅ Yes

Meaning:
The Patch engine is running normally and can perform scans and deployments.

Next Steps:
None if combined with:

  • Low scan age

  • No scan errors


⚠️ [no results]

Meaning:
The endpoint did NOT return a Patch engine status.
Common reasons:

  • Patch tools not installed

  • Patch tools corrupted

  • Process never started

  • AV/AppLocker blocked execution

  • The OS is unsupported

What to check next:

  1. Tools Status Details → confirm Installed Version

  2. Coverage Status Details → Unsupported vs Needs Attention

  3. Scan Errors → likely missing

  4. Restart tanium client service

  5. Redeploy Patch tools package


3. Patch – Scan Age

This question returns the number of days since the last successful patch scan.

Example Output

Days Since Successful Scan Count
1 Day 6
0 Days 5
[no results] 5
More than 30 days ago 1

Interpreting Results

🟢 0 Days

Meaning:
Scan ran recently and is healthy.

🟢 1 Day

Meaning:
Still healthy — this is normal.


⚠️ More than 30 days ago

Meaning:
Extremely stale scan. Patch data is not trustworthy.
These endpoints need remediation.

❗ [no results]

Meaning:
The endpoint did not return scan age data.

Possible causes:

  • Patch tools not installed

  • Unsupported OS

  • Patch engine not running

  • Scan never ran

  • Corrupt scan data

Next steps:

  • Check Coverage Status Details → is it Needs Attention or Unsupported?

  • Check Scan Errors

  • Check Is Process Running

  • Redeploy Patch tools


4. Patch – Scan Errors

This question returns:

  • Scan Configuration ID

  • Error Message

Example Output (your screenshot)

Scan Configuration ID Error Message Count
0 No Scan Errors 12
[no results] [no results] 5

What Each Result Means

🟢 No Scan Errors

Meaning:
Patch scan succeeded or is running normally.

⚠️ [no results]

Meaning:
Endpoint did not return an error message because:

  • Scan never executed

  • Tools not installed

  • Patch engine not running

  • OS unsupported

  • Machine offline

Next Steps:

  • Validate Tools Status Details

  • Validate Patch process

  • Validate OS support

  • Redeploy tools

  • Trigger new scan


5. Endpoint Configuration – Tools Status Details (Patch)

This question returns detailed tool health, including:

  • Installed Version

  • Targeted Version

  • Status

  • Failure Step

  • Installation Blockers

  • Failure Message

Example Output (your screenshot)

Tool Name Installed Version Targeted Version Status Count
Patch 10.7.26.0 10.7.26.0 Installed 12
[no results] [no results] [no results] [no results] 5

How to Interpret

🟢 Installed / Versions Match

Meaning:
Tools are installed correctly and functional.

⚠️ [no results]

Meaning:
The endpoint is missing Patch tools completely.

Root causes:

  • Tools never deployed

  • Unsupported endpoint

  • Agent installation issues

  • AV/AppLocker blocked installation

  • Endpoint offline

  • Manual removal by user/admin

Remediation:

  • Redeploy Patch tools to these endpoints

  • Verify they appear in correct computer groups

  • Check permissions and exclusions


Full Troubleshooting Sequence (Based on Your Data)

Use this exact order for accuracy:

  1. Coverage Status Details

    • Optimal → healthy

    • Needs Attention → go to Scan Age

    • Unsupported → OS upgrade or exclude

  2. Scan Age

    • 0–1 day → healthy

    • 30 days or [no results] → troubleshoot

  3. Scan Errors

    • “No Scan Errors” → engine OK

    • [no results] → likely tools missing or engine down

  4. Is Process Running

    • Yes → Patch engine active

    • [no results] → engine not running → tools issue

  5. Tools Status Details

    • Installed + version match → good

    • [no results] → tools missing → redeploy