Tanium Patch Troubleshooting Guide
This guide documents how to interpret Tanium Patch health using the following questions:
-
Patch – Coverage Status Details
-
Patch – Scan Age
-
Patch – Scan Errors
-
Patch – Is Process Running
-
Endpoint Configuration – Tools Status Details (Patch)
Full Troubleshooting Sequence
Use this exact order for accuracy:
1. Patch – Coverage Status Details
This question returns three columns:
Get Patch - Coverage Status Details from all machines
Example output (like in your screenshot):
1.1 Status Values & What They Mean
✅ Optimal
⚠️ Needs Attention (Detail: Stale Scan Results)
Typical remediation for “Needs Attention / Stale Scan Results”:
🚫 Unsupported
Typical remediation for “Unsupported / CX Unsupported”:
1.2 How to Use “Coverage Status Details” in Practice
2. Patch – Is Process Running
This question returns two values:
Get Patch - Is Process Running from all machines
Yes → Patch engine process is running
No → Patch engine process is running
[noNo results]Results] → Patch engine NOT running or tools missing
Example Output
What Each Result Means
✅ Yes
Meaning: The Patch engine is running normally and can perform scans and deployments.
Next Steps: None if combined with Low scan age and No scan errors
⚠️ [no results]
Meaning: The endpoint did NOT return a Patch engine status.CommonPossible reasons:causes:
- Patch tools not installed
- Patch tools corrupted
- Process never started
- AV/AppLocker blocked
- The OS is unsupported
What to check next:
- Tools Status Details → confirm Installed Version
- Coverage Status Details → Unsupported vs Needs Attention
- Scan Errors → likely missing
- Restart the Tanium client service
- Redeploy the Patch tools package
3. Patch – Scan Age
This question returns the number of days since the last successful patch scan.
Get Patch - Scan Age from all machines
Example Output
Interpreting Results
🟢 0 Days: Scan ran recently and is healthy.❗[no results]: The endpoint did not return scan age data.
Possible causes:
Next steps:
4. Patch – Scan Errors
This question returns:
Get Patch - Scan Errors from all machines
Example Output (your screenshot)
What Each Result Means
🟢 No Scan Errors: Patch scan succeeded or is running normally.Possible causes:
Next Steps:
5. Endpoint Configuration – Tools Status Details (Patch)
This question returns detailed tool health, including:
Get Endpoint Configuration - Tools Status Details contains patch from all machines
Example Output (your screenshot)
How to Interpret
🟢 Installed / Versions Match: Tools are installed correctly and functional.Possible causes:
Remediation: