Skip to main content

Tanium Patch Troubleshooting Guide

https://help.tanium.com/bundle/ug_patch_cloud/page/patch/troubleshooting.html

This guide documents how to interpret Tanium Patch health using the following questions:

  • Patch – Coverage Status Details

  • Patch – Scan Age

  • Patch – Scan Errors

  • Patch – Is Process Running

  • Endpoint Configuration – Tools Status Details (Patch)

Full Troubleshooting Sequence

Use this exact order for accuracy:

  1. Coverage Status Details

    • Optimal → healthy

    • Needs Attention → go to Scan Age

    • Unsupported → OS upgrade or exclude

  2. Scan Age

    • 0–1 day → healthy

    • 30 days or [no results] → troubleshoot

  3. Scan Errors

    • “No Scan Errors” → engine OK

    • [no results] → likely tools missing or engine down

  4. Is Process Running

    • Yes → Patch engine active

    • No → engine not running
    • [no results] → engine not running → tools issue

  5. Tools Status Details

    • Installed + version match → good

    • [no results] → tools missing → redeploy

1. Patch – Coverage Status Details

This question returns three columns:

  • Status – high-level health for Patch on the endpoint

  • Detailwhy that status was assigned

  • Count – number of machines with that Status/Detail combination

Get Patch - Coverage Status Details from all machines

Example output (like in your screenshot):

Status Detail Count
Optimal N/A 11
Unsupported CX Unsupported 5
Needs Attention Stale Scan Results 1

1.1 Status Values & What They Mean

Optimal
  • Meaning: Patch is fully functional on the endpoint.

  • Typical Detail: N/A (no specific issue; everything is fine)

  • What to look for:

    • The majority of your endpoints should be Optimal / N/A.

    • If a machine is Optimal, but you still see patch issues, move on to:

      • Patch – Scan Age

      • Patch – Scan Errors


⚠️ Needs Attention (Detail: Stale Scan Results)

  • Meaning: Patch is installed, but something is wrong that affects its quality or freshness.

  • Common Detail values you’ll see:

    • Stale Scan Results – patch scan data is too old

    • (You may also see other detail strings like tools issues, failed scans, etc., depending on your environment.)

  • What to look for:

    • Use the Detail column to understand the next step:

      • Stale Scan Results → check Patch – Scan Age and Patch – Scan Errors

      • Tool-related text (if present) → check Endpoint Configuration – Tools Status Details (Patch)

    • Check Count to understand the impact:

      • 1–2 machines → one-off endpoint problem

      • Many machines → possible policy, content, or network issue

Typical remediation for “Needs Attention / Stale Scan Results”:

  1. Check Patch – Scan Age on those endpoints.

  2. If scan age is high, run Patch – Scan Errors to see why scans are failing.

  3. Confirm the Patch engine process is running.

  4. If tools look broken, run Endpoint Configuration – Tools Status Details (Patch) to verify.


🚫 Unsupported

  • Meaning: Tanium Patch cannot manage this endpoint for patching.

  • Example Detail:

    • CX Unsupported – the OS/platform is not supported by the Patch module (for example, a consumer/unsupported Windows SKU or an OS version outside the supported matrix).

  • What to look for:

    • Check details to confirm why it’s unsupported:

      • CX Unsupported Usually means this OS edition or version is out of scope for corporate patching via Tanium.

    • Use Count to see if this is:

      • A few test/edge devices → probably fine

      • A lot of production machines → you might have people running unsupported OS builds

Typical remediation for “Unsupported / CX Unsupported”:

  • Validate OS/SKU against your Tanium Patch-supported platform list.

  • For important machines:

    • Plan OS upgrade/rebuild to a supported edition.

  • For non-critical or lab devices:

    • Document that they are out of the Patch scope and handle manually or via another tool.


1.2 How to Use “Coverage Status Details” in Practice

  1. Run 

    Get Patch – Coverage Status Details from all machines
  2. Sort by Status, then Detail.

  3. Interpret:

    • Optimal / N/A → healthy population.

    • Needs Attention / Stale Scan Results (or other issues) → these are your fix-me targets.

    • Unsupported / CX Unsupported → out-of-scope OS/platforms; review and decide whether to remediate or exclude from compliance.

  4. Next Steps by Status:

    • For Needs Attention → drill into:

      • Patch – Scan Age

      • Patch – Scan Errors

      • Patch – Is Process Running

      • Endpoint Configuration – Tools Status Details

    • For Unsupported → validate OS and plan lifecycle/upgrade.



2. Patch – Is Process Running

This question returns two values:

Get Patch - Is Process Running from all machines

 

  • Yes → Patch engine process is running

  • [no results] → Patch engine NOT running or tools missing

Example Output

Patch – Is Process Running Count
Yes 12
[no results] 5


What Each Result Means

✅ Yes

Meaning: 
The Patch engine is running normally and can perform scans and deployments.

Next Steps: 
None if combined with:with Low scan age and No scan errors

  • Low scan age

  • No scan errors


⚠️ [no results]

Meaning: 
The endpoint did NOT return a Patch engine status.
Common reasons:

  • Patch tools not installed

  • Patch tools corrupted

  • Process never started

  • AV/AppLocker blocked execution

  • The OS is unsupported

What to check next:

    • Tools Status Details → confirm Installed Version

    • Coverage Status Details → Unsupported vs Needs Attention

    • Scan Errors → likely missing

    • Restart taniumthe Tanium client service

    • Redeploy

      Redeploythe Patch tools package


3. Patch – Scan Age

This question returns the number of days since the last successful patch scan.

Get Patch - Scan Age from all machines

Example Output

Days Since Successful Scan Count
1 Day 6
0 Days 5
[no results] 5
More than 30 days ago 1

Interpreting Results

🟢 0 Days

:

Meaning:
Scan ran recently and is healthy.

🟢 1 Day

Day:

Meaning:
Still healthy — this is normal.


⚠️ More than 30 days ago

ago:

Meaning:
Extremely stale scan. Patch data is not trustworthy.
These endpoints need remediation.

 [no results]:

Meaning:
The endpoint did not return scan age data.

Possible causes:

  • Patch tools not installed

  • Unsupported OS

  • Patch engine is not running

  • Scan never ran

  • Corrupt scan data

Next steps:

  • Check Coverage Status DetailsisIs it "Needs AttentionAttention" or Unsupported?

  • Check Scan Errors

  • Check "Is Process RunningRunning"

  • Redeploy Patch tools


4. Patch – Scan Errors

This question returns:

  • Scan Configuration ID

  • Error Message

Get Patch - Scan Errors from all machines

Example Output (your screenshot)

Scan Configuration ID Error Message Count
0 No Scan Errors 12
[no results] [no results] 5

What Each Result Means

🟢 No Scan ErrorsErrors:

Meaning:
Patch scan succeeded or is running normally.

⚠️ [no results]:

Meaning:
Endpoint did not return an error message because:

Possible causes:

  • Scan never executed

  • Tools not installed

  • Patch engine is not running

  • OS unsupported

  • Machine offline

Next Steps:

  • Validate Tools Status Details

  • Validate Patch process

  • Validate OS support

  • Redeploy tools

  • Trigger a new scan


5. Endpoint Configuration – Tools Status Details (Patch)

This question returns detailed tool health, including:

  • Installed Version

  • Targeted Version

  • Status

  • Failure Step

  • Installation Blockers

  • Failure Message

Get Endpoint Configuration - Tools Status Details contains patch from all machines

Example Output (your screenshot)

Tool Name Installed Version Targeted Version Status Count
Patch 10.7.26.0 10.7.26.0 Installed 12
[no results] [no results] [no results] [no results] 5

How to Interpret

🟢 Installed / Versions Match

Match:

Meaning:
Tools are installed correctly and functional.

⚠️ [no results]

:

Meaning:
The endpoint is missing Patch tools completely.

RootPossible causes:

  • Tools never deployed

  • Unsupported endpoint

  • Agent installation issues

  • AV/AppLocker blocked installation

  • Endpoint offline

  • Manual removal by user/admin

Remediation:

  • Redeploy Patch tools to these endpoints

  • Verify they appear in the correct computer groups

  • Check permissions and exclusions


Full Troubleshooting Sequence (Based on Your Data)

Use this exact order for accuracy:

  1. Coverage Status Details

    • Optimal → healthy

    • Needs Attention → go to Scan Age

    • Unsupported → OS upgrade or exclude

  2. Scan Age

    • 0–1 day → healthy

    • 30 days or [no results] → troubleshoot

  3. Scan Errors

    • “No Scan Errors” → engine OK

    • [no results] → likely tools missing or engine down

  4. Is Process Running

    • Yes → Patch engine active

    • [no results] → engine not running → tools issue

  5. Tools Status Details

    • Installed + version match → good

    • [no results] → tools missing → redeploy