Hi All,
We have a CentOS 7 installation with Sophos Endpoint software talking to SEC on out Sophos server. Every time the server has been idle for more than 12 hours, it hangs during a scheduled Sophos update. The message log's last entry was the starting of the update and nothing else until I force a restart. This happens every weekend and once when I wasn't in over a day.
Following are from the message log over three weekends and one from Tuesday:
Aug 13 03:48:28 TestSrv systemd: Started "Sophos Anti-Virus update".
Aug 13 03:50:01 TestSrv systemd: Created slice user-0.slice.
Aug 13 03:50:01 TestSrv systemd: Starting user-0.slice.
Aug 13 03:50:01 TestSrv systemd: Started Session 3402 of user root.
Aug 13 03:50:01 TestSrv systemd: Starting Session 3402 of user root.
Aug 13 03:50:01 TestSrv systemd: Removed slice user-0.slice.
Aug 13 03:50:01 TestSrv systemd: Stopping user-0.slice.
Aug 15 10:43:31 TestSrv rsyslogd: [origin software="rsyslogd" swVersion="7.4.7" x-pid="875" x-info="http://www.rsyslog.com"] start
Aug 20 06:13:56 TestSrv systemd: Started "Sophos Anti-Virus update".
Aug 22 14:57:50 TestSrv rsyslogd: [origin software="rsyslogd" swVersion="7.4.7" x-pid="859" x-info="http://www.rsyslog.com"] start
Aug 27 03:01:40 TestSrv systemd: Started "Sophos Anti-Virus update".
Aug 29 09:16:00 TestSrv rsyslogd: [origin software="rsyslogd" swVersion="7.4.7" x-pid="837" x-info="http://www.rsyslog.com"] start
Aug 30 18:46:44 TestSrv systemd: Started "Sophos Anti-Virus update".
Aug 30 18:50:01 TestSrv systemd: Created slice user-0.slice.
Aug 30 18:50:01 TestSrv systemd: Starting user-0.slice.
Aug 30 18:50:01 TestSrv systemd: Started Session 244 of user root.
Aug 30 18:50:01 TestSrv systemd: Starting Session 244 of user root.
Aug 30 18:50:01 TestSrv systemd: Removed slice user-0.slice.
Aug 30 18:50:01 TestSrv systemd: Stopping user-0.slice.
Aug 31 08:59:46 TestSrv rsyslogd: [origin software="rsyslogd" swVersion="7.4.7" x-pid="877" x-info="http://www.rsyslog.com"] start
There is no other logging to indicate what is causing the hanging. The version of Sophos for CentOS is 9 as recommended. I have uninstalled Sophos and will see if the server still hangs over the weekend. We did have an Ubuntu installation where Sophos started miss-behaving as well and had to uninstall it. We did not think too much about it at the time as we know Ubuntu isn't properly supported. We have other servers running CentOS 6.5 without issues.
Has anyone else had same or similar issues and can shed some light on it?
Edit: Additional information. Kernel version is 3.10.0-327.28.3.el7.x86_64 and Sophos SAV version is 9.12.2. It was working fine in early August, which I guess was using version 9.12.0.
TIA,
Vlad
This thread was automatically locked due to age.