Sophos Endpoint: "One or more Sophos services are missing or not running."

Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.


Hi Community,

Below are possible troubleshooting steps (and KB articles for reference) to take when you see an alert in Sophos Central that says "One or more Sophos services are missing or not running" for machines running Sophos Central Endpoint. We will also have recommendations on what information to provide to Sophos Support if none of the suggestions below work or are not applicable. 

 

What does this alert mean?

Services missing or not running usually means that a component has failed to install or update. In some cases, the Operating System or some other third party application may interfere with Sophos services, and would cause the service(s) to not start.

 

What to do

 

For Mac OS:

 

For Windows OS:

  1. If the Sophos AutoUpdate service is not started or is missing, this needs to be resolved first. If this service is not started (or not installed), Updating will not occur and other services will not start.
  2. Re-create the Autoupdate cache. When Sophos updates, it downloads the update files for all components installed on the endpoint and these are run in some particular order to facilitate the update. If there are files missing, the update could fail and services will be missing/not started.
  3. If #2 does not work, determine which service is not running or is missing. This is usually an indication that the update has failed because a certain component did not uninstall, and/or install successfully.
  4. If the service still would not start: Raise a support case with the following information, at the very least:

 

Additional suggestions for troubleshooting are welcome. This post may be updated periodically.



Updated disclaimer
[edited by: Qoosh at 10:03 PM (GMT -7) on 31 Mar 2023]