Review troubleshooting tasks for common issues.

Troubleshoot Connect by using log files and the solutions to common issues. If you cannot resolve the issues, collect support information.

Collect logs

To collect logs, click Help and open the Troubleshooting tab. Select whether you want to include database backups and click Create Package. After the support package is created, click Download Package to download the package that includes logs to send to support. If you included database backups, the backup files are named connect-<version>-<migrationCount>.db.bak-<backupTimestamp> where:

  • <version> is the current version or pre-4.12.1
  • <migrationCount> is the state of the database schema
  • <backupTimestamp> is the milliseconds since epoch timestamp format when the backup was created

Configure logs

Adjust log expiration

To adjust the number of days before log files are removed, click Settings on the Connect Overview page and navigate to the Configuration tab. Edit the number of days in the Connection Run Log Expiration field and click Save.

Adjust log level

To adjust the log level, choose a log level from the Connect Service Log Level menu and click Save.

View logs

Service logs

The Connect service records logs in the \Program Files\Tanium\Tanium Module Server\services\connect-files\logs\server.log file. This file is in JSON format by default, but you can use the Bunyan CLI tool to view the logs. From the \Program Files\Tanium\Tanium Module Server\services\connect-files\ directory, run the following command:

..\connect-service\node ..\connect-service\node_modules\bunyan\bin\bunyan logs\server.log

Search this log for the following message to tell when the Connect service starts:

Tanium Connect Starting

Connection run logs

Connections generate a log file for each run of the connection. The run logs are in the \Program Files\Tanium\Tanium Module Server\services\connect-files\logs\connections\ directory.

Connect configuration state

Connect stores information about connections and user settings in the \Program Files\Tanium\Tanium Module Server\services\connect-files\config\connect.db file.

Do not edit the connect.db file unless advised by Tanium Support.

Test connections

If you have trouble with a connection, you can run the connection outside of the scheduled intervals.

  1. Send a test connection.

    From the Connect Overview page, scroll to the Connections section. Select the checkbox next to the connection, click Run Now, and confirm to run the connection.
  2. Click the connection and open the Logs tab to view information about each run for that connection. Expand an individual row to view the log.

    If you need more log data, open the Details tab, update the Log Level value, and click Save. Run the connection again to view the log with the updated log level.

  3. If the IP address for a connection is on an internal network, only a Tanium administrator can run the connection by default.
    Click Settings on the Connect Overview page. On the Configuration tab, select Internal IPs to allow anyone to run connections to IPs on an internal network.

Troubleshoot issues

If a connection fails to send any data in a 60 minute period, Connect automatically terminates the connection.

Issue: Cannot connect to Connect service

  1. Verify that the Connect service is running on your Module Server.

    To view the running services, click Start > Run. Type services.msc and click OK. Verify that Connect is in the list and that the service is running.
  2. Check the service logs for any errors or messages about insufficient rights for the user. The Connect service records logs in the \Program Files\Tanium\Tanium Module Server\services\connect-files\logs\server.log file.

Issue: Failed connections to destinations

Before your connections can successfully send data to a destination, your Tanium Cloud instance and network allowlist must be configured. Note the following:

  • Contact Tanium Support with the destination fully qualified domain name (FQDN) or IP address, port, and protocol to submit an external access request.

  • Tanium Cloud does not support non-TLS plaintext HTTP URLs.
  • Tanium does not support sending data over TCP port 25 outbound. If you submit an external access request for an SMTP email server destination (default TCP port 465 or TCP port 587), you can only associate the port with 1 FQDN or IP address.

  • For other destinations, you can reuse a port for multiple destination FQDNs or IP addresses.

  • Your Tanium Cloud instance has a proxy cluster with 2 public IP addresses. If a destination is in your network, add inbound traffic from these IP addresses to your network allowlist.

For more information, see Tanium Cloud Deployment Guide: Proxy access.

Issue: <no value> in Tanium Data Service output

  1. Verify that the sensor for the saved question is registered. For more information, see Tanium Console User Guide: Display sensor collection registration details.
  2. If the sensor is not registered, register it for collection. For more information, see Tanium Console User Guide: Register or unregister sensors for collection.
  3. If you recently registered a sensor and want to see immediate results before the next scheduled collection, you can manually start the collection. For more information, see Tanium Console User Guide: Manually start collection.

Issue: Connection does not export all intended data

Connections use the owner's role permissions to access content. If the connection owner has insufficient permission for content that a connection requires, such as inability to view a computer group, the connection might not fully export the data that you intend to export.

Do one of the following:

Problem: Scheduled connection owned by a deleted user no longer runs

Scheduled connections require an existing Tanium user account owner to run scheduled instances. If the scheduled connection owner is deleted, future scheduled instances of that connection do not run.

Do one of the following:

Uninstall Connect

The basic Connect module uninstallation is designed so that the data you have collected is restored if you later decide to reinstall Connect. In some cases, you might want to start "clean" and not restore the data. To do this, you must manually remove some files.

Consult with Tanium Support before you uninstall or reinstall Connect.

Uninstall Connect so data is restored on reinstall

  1. Sign in to the Tanium Console as a user with the Administrator role.
  2. From the Main menu, go to Administration > Configuration > Solutions.
  3. Under Connect, click Uninstall.
  4. Review the summary and click Uninstall.
  5. When prompted to confirm, enter your password.

If you later import the Connect solution, the previous data is restored.

Uninstall Connect so you start fresh when you reinstall

  1. Uninstall Connect so data is restored on reinstall.
  2. Manually delete the \Program Files\Tanium\Tanium Module Server\services\connect-files\ directory.

Deleting the connect-files directory removes all existing Connect data. All logs, output, the Connect database, and any other Connect data is deleted. If you later import the Connect solution, the previous data is not restored.

Contact Tanium Support

To contact Tanium Support for help, sign in to