Troubleshooting Direct Connect

To collect and send information to Tanium for troubleshooting, collect logs and other relevant information.

Generate a support package

Collect information about the current state of the Direct Connect service to use for troubleshooting. The information is saved as a ZIP file that you can download with your browser.

  1. From the Direct Connect Home page, click Help , then the Troubleshooting tab.
  2. Click Generate Support Package.
  3. Click Download Support Package to download the ZIP file to the local download directory.
  4. Contact Tanium Support to determine the best option to send the ZIP file. For more information, see Contact Tanium Support.

Change the logging level

If you need greater verbosity in the logs, you can change the log level.

  1. From the Direct Connect Home page, click Help , then the Troubleshooting tab.
  2. Adjust the Log Level as needed.

    Possible values are: trace, debug, info (default), warn, error, fatal.

This update changes the log level for future logging. It does not affect the data that is available in the support package for previously logged events.

Troubleshoot endpoint connection issues

If you are unable to establish an endpoint connection, check the status of the Deploy Direct Connect - Open Session - operating system - session ID action from the Action History page.

If the action ran, but was not successful, check the <Tanium Client>/Logs/extensions0.txt log on the endpoint. Make sure that the endpoint can connect to the Module Server using the Fully Qualified Domain Name and Port that you configured on the Endpoint Connection tab in the Direct Connect settingsTanium as a Service using its fully qualified domain name and port 17486.

If the action did not run on the endpoint, make sure that the endpoint is a member of the Direct Connect action group and has the latest tools installed.

The statuses of the Deploy Direct Connect - Tools and Deploy Direct Connect - Configure Extension saved actions might also provide useful troubleshooting information.

Troubleshoot connection issues through a zone proxy

To use Direct Connect with endpoints that connect to the Module Server through a Zone Server, you must install and configure the Direct Connect Zone Proxy. For more information, see Configure Zone Proxies.

If you are unable to establish an endpoint connection after installing and configuring the Direct Connect Zone Proxy, check the Direct Connect Zone Proxy log for errors: <Tanium>/TaniumDirectConnectZoneProxy/logs/proxy.log.

Uninstall Direct Connect

If you need to uninstall Direct Connect, first clean up the Direct Connect artifacts on endpoints and then uninstall Direct Connect from the server.

Direct Connect is a shared service that is used by several Tanium solutions. If Direct Connect is in use by another Tanium solution, uninstalling Direct Connect or removing the tools from endpoints could have unintended consequences. Consult your TAM to determine whether uninstalling Direct Connect is advisable in your environment.

Remove Direct Connect content and tools from endpoints

Each operating system has its own remove action. Therefore, you must select a group of endpoints for cleanup that has the same operating system.

  1. From the Main menu, click Modules > Interact.
  2. Ask a question to target the endpoints from which you want to remove Direct Connect content and tools. For example, Get Direct Connect - Tools Version from all machines.
  3. Select the row for the endpoints from which you want to remove the Direct Connect tools (either Windows Package Installed, Mac Package Installed or Linux Package Installed).
  4. Click Deploy Action.
  5. On the Deploy Action page, enter Direct Connect - Remove in the Enter package name here field.
  6. Select the Direct Connect - Remove Tools [operating system] action, where operating system matches the operating system of the endpoints that you selected.
  7. Click Show preview to continue.
  8. A results grid displays at the bottom of the page showing you the targeted endpoints for your action. If you are satisfied with the results, click Deploy Action.

Remove the Direct Connect solution from the Tanium Module Server

  1. From the Main menu, go to Administration > Configuration > Solutions.
  2. In the Content section, select the Direct Connect row.
  3. Click Delete Selected and then click Uninstall to complete the process.

Contact Tanium Support

To contact Tanium Support for help, send an email to [email protected].