Reference: TanOS menu map
The following tables list the available options in the TanOS menus.
Not all menu paths are available on every server or in every deployment.
TanOS menu
The main TanOS console menu contains the following options.
Option | Menu |
---|---|
1 | Tanium Installation Menu |
2 | Tanium Operations Menu |
3 | Tanium Support Menu |
4 | Status Menu |
A | Appliance Configuration Menu |
B | Appliance Maintenance Menu |
C | User Administration Menu |
P | Password change (current user) |
Q | View end user license agreement (EULA) |
@ | About this appliance |
H | Help |
Z | Log out |
Common menu options
The following table lists menu items that are found on many screens in the TanOS console.
Menu Item | Description |
---|---|
H - Help | Opens a screen providing additional details. |
R - Return to previous menu | Returns to the previous screen. |
RR - Return to top | Return to the main TanOS menu. |
Tanium Installation Menu
Enter 1 to access the installation menu.
M - Manage Appliance Array For more information, see Installing and managing an Appliance Array. |
||
M | C - Create Appliance Array | |
M | A - Add Member | |
M | F - Refresh Appliance Array | |
M | I - Install Pending Role Changes | |
M | X - Reset Appliance Array | |
M | n - line number of array member | |
M | n | T - Assign Role: Tanium Server |
M | n | M - Assign Role: Tanium Module Server |
M | n | Z - Assign Role: Tanium Zone Server |
M | n | U - Cancel pending role change |
M | n | P - Promote member to manager |
M | n | D - Delete member |
1 - Install Tanium Server (All-in-one) | ||
2 - Install Tanium Server Service | ||
3 - Install Tanium Module Server Service | ||
4 - Install Tanium Zone Server Service | ||
5 - Install Tanium Cloud Access Point Service | ||
U - Upgrade Tanium Software | ||
E - Remove Tanium Zone Server Hub Add-On | ||
D - Tanium Direct Connect Zone Proxy For more information, see Installing a Direct Connect Zone Proxy. |
||
D | T - Download from Tanium | |
D | L - List Installed DEC Proxy Versions1 | |
D | V - View DEC Provision Instructions2 | |
D | X - Remove DEC Proxy2 | |
1Tanium Server only 2Tanium Zone Server only |
Tanium Operations Menu
Enter 2 to access the operations menu. For more information, see Reference: Tanium Operations menu.
1 - Tanium Service Control | |||
1 | x - service name | 1 - Start service | |
1 | x | 2 - Stop service | |
1 | x | 3 - Restart service | |
1 | x | 4 - Disable service | |
1 | x | 6 - Status details | |
1 | A - Restart all enabled Tanium services | ||
1 | B - Stop all Tanium services | ||
1 | C - Start all Tanium services | ||
1 | D - Disable all Tanium services | ||
1 | E - Enable all Tanium services | ||
2 - Tanium Configuration Settings | |||
2 | 1 - Edit Tanium Server Settings1 | ||
2 | 2 - Edit Tanium Server TDL Settings1 | ||
2 | 3 - Add Tanium Server TDL Auth User1 | ||
2 | 4 - Add Tanium Server TDL Auth Cert 1 | ||
2 | 5 - Edit Tanium Module Server Settings2 | ||
2 | 6 - Edit Tanium Module Server TDL Settings2 | ||
2 | 7 - Add Tanium Module Server TDL Auth User2 | ||
2 | 8 - Add Tanium Module Server TDL Auth Cert2 | ||
2 | 9 - Edit Tanium Zone Server Settings3 | ||
2 | 10 - Edit Zone Server List3 | ||
2 | 11 - Edit Isolated Subnets List3 | ||
2 | 12 - Edit Separated Subnets List3 | ||
2 | 13 - Control Root CA Certs | ||
4 - Install custom SOAP certificates | |||
5 - Manage custom signing keys | |||
5 | L - List content signing keys | ||
5 | A - Add content signing key | ||
5 | D - Delete content signing key | ||
6 - Download public key | |||
7 - Download SOAP certificate | |||
9 - Import CAC certificate | |||
A - Configure Module Server(s)1 A - Register Module Server2 |
|||
A | P - Promote TMS1 | ||
A | S - Assign TMS Role1 | ||
A | S | x - TMS line number1 | S - Enable TMS sync source1 |
A | S | x | T - Enable TMS sync target1 |
A | S | x | D - Disable TMS sync1 |
A | 1 - Step 1 - Configure Module Server Address1 | ||
A | 2 - Step 2 - Register Module Server2 | ||
A | 3 - Read about Remote Module Server configuration5 | ||
B - Configure Tanium cluster1 | |||
B | 1 - Step 1 - Initialize cluster | ||
B | 2 - Step 2 - Join cluster | ||
B | 3 - Read about cluster operations | ||
B | A - Database Server Failover | ||
B | S - Replication Status | ||
B | L - Remove Cluster | ||
B | B - Reinitialize Replication | ||
B | C - SSH Key management | ||
B | D - IPsec management | ||
C - Manage content | |||
C | 1 - Install airgap content | ||
C | 2 - Airgap usage report | ||
C | 3 - Prune airgap content | ||
C | 4 - Manage web server content | ||
C | B - Set manifest | ||
D - Configure Module Server sync2 | |||
D | 1 - Show Detailed Status | ||
D | 2 - Configure IPSEC | ||
D | 1 - Display Local IPSEC host key | ||
D | 2 - Display IPSEC | ||
D | 3 - Configure IPSEC | ||
D | 4 - Delete IPSEC | ||
D | 5 - Restart IPSEC | ||
D | 6 - Test IPSEC | ||
D | 3 - Disable TMS Sync | ||
D | 4 - Sync Now | ||
D | 5 - Schedule Sync | ||
D | V - View Sync Log | ||
I - Import public key to Tanium Zone Server3 | |||
M - Module operations4 | |||
M | I - Install/Upgrade DEC Proxy5 | ||
M | V - View DEC Provision Instructions5 | ||
M | X - Remove DEC Proxy5 | ||
P - Manage Cloud Access Point6 | |||
P | C - Configure Cloud Access Point | ||
P | S - Manage Cloud Access Point Service | 1 - Start service | |
P | S | 2 - Stop service | |
P | S | 3 - Restart service | |
P | S | 4 - Disable service | |
P | S | 5 - Enable service | |
P | S | 6 - Status details | |
X - Advanced operations7 For more information, see Reference: Advanced Operations menu. |
|||
X | 2 - Toggle UseTBBAllocatorStats | ||
X | 3 - Generate new keys (tanium.pub) | ||
X | 4 - Manage HTML banner | ||
X | 5 - Generate reporting keys (Zone Server to Server) | ||
X | 6 - Generate reporting keys (Client to Server) | ||
X | 7 - Disable SAML SSO | ||
1Tanium Server only |
Tanium Support Menu
Enter 3 to access the Tanium Support Menu. For more information, see Reference: Tanium Status and Support menus.
1 - Tanium Log Files | |||
1 | 1 - TanOS Appliance | ||
1 | 1 | 1 - TanOS Log | V - View file |
1 | 1 | 1 | F - Follow log file growth |
1 | 1 | 1 | T - Delete content of log file |
1 | 1 | 1 | E - Export to outgoing (SFTP) |
1 | 1 | 2 - Upgrade log | V - View file |
1 | 1 | 2 | F - Follow log file growth |
1 | 1 | 2 | T - Delete content of log file |
1 | 1 | 2 | E - Export to outgoing (SFTP) |
1 | 1 | 3 - Health log | V - View file |
1 | 1 | 3 | F - Follow log file growth |
1 | 1 | 3 | T - Delete content of log file |
1 | 1 | 3 | E - Export to outgoing (SFTP) |
1 | 1 | 4 - Health failure log | V - View file |
1 | 1 | 4 | F - Follow log file growth |
1 | 1 | 4 | T - Delete content of log file |
1 | 1 | 4 | E - Export to outgoing (SFTP) |
1 | 1 | 5 - Messages log | V - View file |
1 | 1 | 5 | F - Follow log file growth |
1 | 1 | 5 | T - Delete content of log file |
1 | 1 | 5 | E - Export to outgoing (SFTP) |
1 | 1 | 6 - License log | V - View file |
1 | 1 | 6 | F - Follow log file growth |
1 | 1 | 6 | T - Delete content of log file |
1 | 1 | 6 | E - Export to outgoing (SFTP) |
1 | 2 - Tanium Server1 | ||
1 | 2 | 1 - Tanium Server log (log0.txt) | V - View file |
1 | 2 | 1 | F - Follow log file growth |
1 | 2 | 1 | T - Delete content of log file |
1 | 2 | 1 | E - Export to outgoing (SFTP) |
1 | 2 | 2 - Tanium Server TDL log (log0.txt) | V - View file |
1 | 2 | 2 | F - Follow log file growth |
1 | 2 | 2 | T - Delete content of log file |
1 | 2 | 2 | E - Export to outgoing (SFTP) |
1 | 2 | 3 - Tanium Server RBAC log (rbac0.txt) | V - View file |
1 | 2 | 3 | F - Follow log file growth |
1 | 2 | 3 | T - Delete content of log file |
1 | 2 | 3 | E - Export to outgoing (SFTP) |
1 | 2 | 4 - Tanium Server PAM4 log (tanium_pam4.log) | V - View file |
1 | 2 | 4 | F - Follow log file growth |
1 | 2 | 4 | T - Delete content of log file |
1 | 2 | 4 | E - Export to outgoing (SFTP) |
1 | 2 | 5 - Tanium Server workbenches (workbenches_manager.log) |
V - View file |
1 | 2 | 5 | F - Follow log file growth |
1 | 2 | 5 | T - Delete content of log file |
1 | 2 | 5 | E - Export to outgoing (SFTP) |
1 | 2 | 6 - Tanium Server signature verifier (signature_verifier.log) |
V - View file |
1 | 2 | 6 | F - Follow log file growth |
1 | 2 | 6 | T - Delete content of log file |
1 | 2 | 6 | E - Export to outgoing (SFTP) |
1 | 2 | 7 - Tanium Server DB upgrade log (database-upgrade0.txt) |
V - View file |
1 | 2 | 7 | F - Follow log file growth |
1 | 2 | 7 | T - Delete content of log file |
1 | 2 | 7 | E - Export to outgoing (SFTP) |
1 | 2 | 8 - Tanium Server Auth0 log (auth0.txt) |
V - View file |
1 | 2 | 8 | F - Follow log file growth |
1 | 2 | 8 | T - Delete content of log file |
1 | 2 | 8 | E - Export to outgoing (SFTP) |
1 | 3 -Tanium Module Server2 | ||
1 | 3 | 1 - Tanium Module Server log (log0.txt) |
V - View file |
1 | 3 | 1 | F - Follow log file growth |
1 | 3 | 1 | T - Delete content of log file |
1 | 3 | 1 | E - Export to outgoing (SFTP) |
1 | 3 | 2 - Tanium Module Server TDL log (log0.txt) |
V - View file |
1 | 3 | 2 | F - Follow log file growth |
1 | 3 | 2 | T - Delete content of log file |
1 | 3 | 2 | E - Export to outgoing (SFTP) |
1 | 3 | 3 - TMS PluginsManager log (plugins_manager.log) |
V - View file |
1 | 3 | 3 | F - Follow log file growth |
1 | 3 | 3 | T - Delete content of log file |
1 | 3 | 3 | E - Export to outgoing (SFTP) |
1 | 4 - Tanium Zone Server5 | ||
1 | 4 | V - View file | |
1 | 4 | F - Follow log file growth | |
1 | 4 | T - Delete content of log file | |
1 | 4 | E - Export to outgoing (SFTP) | |
1 | 5 - PostgreSQL6 | ||
1 | 5 | x - PostgreSQL log file name | V - View file |
1 | 5 | x | F - Follow log file growth |
1 | 5 | x | E - Export to outgoing (SFTP) |
2 - Tanium Module log files2 | |||
2 | x - Module name | ||
3 - Database Operations6 | |||
3 | 1 - Display Postgres log file | ||
3 | 2 - View Postgresql config files | ||
3 | 3 - Display Postgres control data | ||
3 | 4 - Enable full Postgres audit logs | ||
3 | D - Database memory plan | V - View DB memory plan settings | |
3 | D | S - Select DB memory plan | |
3 | D | A - Apply DB memory plan | |
3 | M - Monitor database | ||
3 | Q - Manage database queries | S - Select query | |
3 | Q | X - Execute query | |
3 | Q | V - View query | |
3 | Q | Q - View query results | |
3 | S - Replication status | ||
3 | F - Database server failover | ||
3 | I - Reinitialize replication | ||
3 | C - Reset cluster role | ||
4 - Run Network Diagnostics | |||
4 | 1 - Ping Remote System | ||
4 | 2 - Test Remote Port (TCP) | ||
4 |
3 - Trace Path |
||
4 | 4 - Resolve Name | ||
4 | 5 - Check IPSEC | ||
4 | 6 - Listening Ports | ||
4 | 7 - Show Firewall | ||
5 - Run Health Check | |||
6 - Display Last Scheduled Health Check Results | |||
7 - Appliance Hardware Report | |||
A - Run TSG (Tanium Support Gatherer) | |||
B - Run TCPdump | |||
P - Performance Monitoring | |||
P | 1 - Run SAR command | ||
P | 2 - Export SAR snapshot | ||
P | 3 - Export SAR performance data | ||
P | 4 - Combine SAR files | ||
P | I - Run iotop command | ||
P | P - Run perf top command | ||
P | T - Run htop command | ||
X - Advanced Support | |||
X | 1 - Copy Core Files | ||
X | 2 - Generate Process Memory Dump | ||
X | 3 - Directory Space Usage | ||
X | V - Internal Tanium VPN Connection | ||
1Tanium Server only |
Status Menu
Enter 4 to access the Status Menu. For more information, see Reference: Tanium Status and Support menus.
1 - System Status | |
1 | 1 - OS Status |
1 | 2 - Network Status |
2 - Tanium Status Menu | |
2 | x - service name |
3 - Appliance Status Menu | |
3 | 1 - Appliance version details |
3 | 2 - Appliance status (OS) |
3 | 3 - Appliance status (HW) |
Appliance Configuration Menu
Enter A to access the appliance configuration menu. The following table lists the options within the appliance configuration menu. For more information and procedures, see Reference: Appliance configuration.
1 - Hostname/DNS configuration | ||||
1 | 1 - Manage hostname/domain name | |||
1 | 2 - Manage DNS server | |||
1 | 3 - Edit hosts file | |||
2 - Networking configuration | ||||
2 | 1 - Network interfaces | |||
2 | 2 - IPSEC configuration | |||
2 | 3 - Routing configuration | |||
2 | 4 - Restart networking | |||
2 | T - NIC teaming | A - Create a network team | ||
3 - NTP configuration | ||||
4 - Syslog configuration | ||||
4 | 1 - Check current status | |||
4 | 2 - View trust certificate | |||
4 | 3 - Upload trust certificate | |||
4 | 4 - Remove trust certificate | |||
4 | 5 - Configure syslog forwarding | |||
5 - SNMP configuration | ||||
5 | U - Change the username | |||
5 | L - Change the location | |||
5 | C - Change the contact | |||
5 | V - View SNMP service status | |||
5 | D - Stop the SNMP service | |||
5 | S - Set password and start the SNMP service | |||
6 - Module file share configuration2 | ||||
6 | 1 - Create a new Connect mount | |||
6 | 2 - Create a new Detect mount | |||
6 | 3 - Create a new Trends mount | |||
6 | 4 - Delete an existing Connect mount | |||
6 | 5 - Delete an existing Detect mount | |||
6 | 6 - Delete an existing Trends mount | |||
6 | A - List existing mounts | |||
6 | B - Test existing mounts | |||
6 | C - Re-attempt mounts | |||
7 - Reset all NICs to DHCP7 | ||||
A - Security | ||||
A |
|
A - Add rule to allow inbound SSH | ||
A | D - Delete rule to allow inbound SSH | |||
A | 3 - Configure SSH banner | |||
A | 4 - Display SSH fingerprints | |||
A | 5 - Regenerate SSH host keys | |||
A | A -LDAP CA certificate management6 | |||
A | A | 1 - Add certificate | ||
A | A | 2 - Import certificate | ||
A | A | 3 - Enable LDAPS configuration | ||
A | A | 4 - Disable TLS certificate validation | ||
A | A | 5 - List certificates | ||
A | A | S - Sync Configuration to Peer TS | ||
A | B -Database certificate management6 | |||
A | B | 1 - Import server certificate | ||
A | B | 2 - Export server certificate | ||
A | B | 3 - Import client certificate | ||
A | B | L - List certificates | ||
A | P - Security policy | |||
A | P | 1 - Password lifetime | ||
A | P | 2 - Password history reuse limit | ||
A | P | 3 - Password minimum length | ||
A | P | 4 - Password minimum characters changed | ||
A | P | D - Login failure delay | ||
A | P | E - Expired passwords effect | ||
A | P | L - Account lockout time | ||
A | P | M - Maximum concurrent logins | ||
A | X - Advanced security | |||
A | X | 1 - FIPS 140-2 mode (disabled/enabled) | ||
A | X | 2 - AIDE | ||
A | X | 4 - Toggle SELinux mode (permissive/enforcing) | ||
A | X | 5 - Set menu timeout | ||
I - iDRAC management8 | ||||
I | N - iDRAC network configuration | |||
I | P - Set tanremote password | |||
I | E - Enable tanremote password | |||
I | D - Disable tanremote password | |||
I | C - Close all iDRAC sessions | |||
I | K - Reset iDRAC | |||
X - Advanced configuration | ||||
X | 3 - Change active partition9 | |||
X | 4 - Change RAID controller key8 | |||
X | 5 - Export RAID controller key8 | |||
X | 6 - Export grub key | |||
X | 7 - Generate new grub key | |||
1Tanium Server only |
Appliance Maintenance Menu
Enter B to access the appliance maintenance menu. The following table lists the options within the appliance maintenance menu. For more information and procedures, see Maintaining the Tanium Appliance.
1 - Backup | ||
1 | Automatic Backups | |
1 | E - Set encryption key | |
1 | C - Configure automatic backup | N - Configure core backup |
1 | C | F - Configure comprehensive backup |
1 | A - Run automatic backup now | |
1 | S - Schedule automatic backup | N - Schedule core backup |
1 | S | F - Schedule comprehensive backup |
1 | Manual Backups | |
1 | P - Partition sync | |
1 | N - Core backup | |
1 | F - Comprehensive backup | |
1 | 4 - Backup Tanium database | |
1 | 5 - List database backups (deprecated) | |
2 - Alerting | ||
2 | 1 - Configure syslog destination | |
2 | 2 - Configure SMTP destination | |
2 | 3 - Configure alerts | |
2 | 4 - Status | |
3 - Upgrade TanOS | ||
5 - Shell keys | ||
5 | 1 - Validate response | |
5 | 2 - Remove shell access | |
5 | 3 - Launch shell | |
5 | O - Open read only restricted shell | |
5 | W - Request read write restircted shell activation | |
5 | F - Request full shell activation | |
5 | L - Shell key listing | |
5 | A - Revoke all shell keys | |
A - Clean directories | ||
A | 1 - SFTP (in/out) | |
A | 2 - Cores | |
A | 3 - Tanium application logs | |
A | 4 - Tanium TSG HTTP files | |
A | 5 - Tanium Connect output logs | |
A | T - /tmp directory | |
B - Reboot/Shutdown | ||
B | 1 - Reboot the appliance | |
B | 2 - Shutdown the appliance | |
C - Maintenance mode | ||
C | 1 - Clear maintenance action | |
E - Enable alt partitions | ||
I - Increase storage | ||
S - OS services | ||
S | 1 - ntpd | 1 - Start service |
S | 1 | 2 - Stop service |
S | 1 | 3 - Restart service |
S | 1 | 4 - Disable service |
S | 1 | 5 - Enable service |
S | 1 | 6 - Status details |
S | 2 - sshd | 1 - Start service |
S | 2 | 2 - Stop service |
S | 2 | 3 - Restart service |
S | 2 | 4 - Disable service |
S | 2 | 5 - Enable service |
S | 2 | 6 - Status details |
T - Tokens download | ||
X - Advanced configuration For more information, see Reference: Advanced Configuration menu. |
||
X | 1 - Install firmware updates8 | |
X | 2 - Appliance reset | 1 - Software reset |
X | 3 - Re-apply ACLs | |
X | 5 - View TanOS partition sync log file | |
8physical Tanium Appliances only |
User Administration Menu
Enter C to access the user administration menu. For more information and procedures, see Reference: User Administration menu.
U - TanOS user management | ||
U | x - individual user | A - Manage SSH authorized keys |
U | x | P - Manage SSH key pair |
U | x | L - Reset SSH lockout |
U | x | C - Change/enable password |
U | x | N - Disable password access |
U | x | M - Configure multi-factor authentication |
U | x | E - Enable account |
U | x | D - Disable account |
U | x | X - Delete user |
U | x | F - Edit known hosts file |
U | A - Add system user | |
I - Recent login information | ||
I | A - View last 20 successful logins | |
I | B - View last 20 failed logins | |
I | C - View login statistics | |
M - Multi-Factor Global Settings | ||
M | K - Require key authentication | |
M | P - Require password authentication | |
M | M - Require multi-factor authentication | |
M | X - Reset multi-factor settings | |
A - AD/LDAP TanOS Authentication | ||
A | M - Manage AD/LDAP Certificate | I - Import Certificate |
A | M | P - Paste Certificate |
A | M | E - Export Certificate |
A | M | V - View Certificate and Details |
A | M | D - Delete Certificate |
A | C - Configure AD/LDAP TanOS Authentication | E - Enable [true] |
A | C | D - Domain [tanos.lab] |
A | C | H - Host [tanos-win2022-server.tanos.lab] |
A | C | P - Port [389] |
A | C | C - Bind Credentials [[email protected]] |
A | C | B - Base Search DN [cn=users,dc=tanos,dc=lab] |
A | C | S - Schema [Active Directory] |
A | C | Q - Referrals [false] |
A | C | K - SSH Public Key Attribute [sshPublicKey] |
A | C | U - Users Filter [] |
A | C | G - Groups Filter [(cn=TanOS*)] |
A | C | M - TanOS Roles Mapping |
A | C | V - Validate Configuration |
A | C | A - Activate Configuration Changes |
A | W - Walkthrough Configuration | |
A | S - Detailed Status | |
A | V - Verify AD/LDAP User or Group | U - Verify AD/LDAP User |
A | V | G - Verify AD/LDAP Group |
A | T - Troubleshooting | S - Manage System Security Services Daemon (sssd) |
A | T | D - Enable Debug Logging |
A | T | V - View Domain Log File |
A | T | L - Logoff User |
A | E - Export configuration to SFTP outgoing | |
A | I - Import configuration from SFTP incoming | |
A | X - Reset ALL AD/LDAP TanOS Auth Settings | |
L - Local Tanium user management | ||
L | 1 - Add local user | |
L | 2 - Manage local users | |
L | A - Enable/disable local authentication service | |
L | B - Security policy local authentication service | |
L | C - Check local authentication contents |
Last updated: 5/30/2023 3:35 PM | Feedback