To collect and send information to Tanium for troubleshooting, collect log and other relevant information.

Collect logs

The information is saved as a compressed ZIP file that you can download with your browser.

  1. From the Discover Home page, click Help , then the Troubleshooting tab.
  2. Click Collect.
    A discover-support.[timestamp].zip file downloads to the local download directory.
  3. Attach the ZIP file to your Tanium Support case form or send it to your TAM.

Tanium Discover maintains logging information in the discover.log file in the <Module Server>/services/discover-service-files/discover.log directory.

View Discover scan ranges

You might want to see the ranges that are scanned before you run discovery, or to troubleshoot discovery that has already run. To see the calculated gaps between the managed interfaces, use the Discover Scan Range and Discover Scan Range - Unix sensors. The Discover Scan Range - Unix sensor is for Solaris and AIX platforms.

For example, you might use the question: Get Computer Name and Operating System and Tanium Client IP Address and Discover Scan Range and Discover Scan Range - Unix from all machines. The results display the range between each of the managed endpoints and its forward and backward peers.

Problem: No results from running a scan

To return results, Discover tools must be distributed to the endpoints. If you do not see results:

  • Check the configuration of the Discover action group. See Configure Discover action group.
  • Check the status of the Discover action group. From the main menu, go to Actions > Scheduled Actions.

Problem: Some endpoints are not scanning

You might find that some endpoints are not scanning. For example, the question: Get Discover Last Scan Range from all machines returns [no results].

Try adjusting the Start at time of the scheduled action to a few minutes after the Start Time of the configured scan window in the profile.

  1. Get the start time of the start window for your profile. From the Discover menu, click Profiles. Hover over the profile_name and click Edit . In the Scan Window section, note the value of the Start Time setting.
  2. From the Main menu, click Actions > Scheduled Actions. Click the Tanium Discover action group.
  3. Select the scheduled action that is associated with the profile. Choose Discover Content - Execute Scan [profile_name] or Discover Content - Execute Scan for non-Windows [profile_name]. Click Edit.
  4. Edit the Start at time to start a few minutes after the Start Time you found in your profile.

FAQ: Why is the number of managed interfaces higher than the system status?

If you compare the number of managed interfaces in Discover, you might notice that the number is often higher than the number of Tanium Clients that are reported on the System Status page.

This disparity is expected. Interfaces are unique MAC addresses. One Tanium Client with multiple network interface controllers (NICs) displays as multiple interfaces in Discover. Virtualization software can increase the number of interfaces reported for a computer, if the computer has multiple virtual machines running.

Uninstall Discover

  1. From the Main menu, click Tanium Solutions. Under Discover, click Uninstall. Click Proceed with Uninstall to complete the process.
  2. Delete any remaining Discover-related scheduled actions and action groups. For more information, see Tanium Console User Guide: Delete an action group.

  3. Check for Discover artifacts on your endpoints. Ask the question: Get Has Discover Artifacts = "true" from all machines. If any endpoints are returned by this question and you want to clean the artifacts off the endpoint, contact your TAM.
  4. Check for Discover plugin schedules. From the Main menu, click Configuration > Common > Plugin Schedules. If plugin schedules exist for Discover, contact your TAM.