This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Update Manager in Sophos Enterprise Console is failing to update since 2pm yesterday

We got this email alert from Enterprise Console:

The time since an update occurred has exceeded the critical threshold. 

I can see in Update Manager that our subscription has been updated yesterday to 10.6.3, which is fine:

However since then updates fail:

Updates broke 2pm yesterday, so we're almost 24 hours behind.

We are running Sophos Enterprise Console 5.3.1 and updating directly from Sophos, there are no child servers etc.

Here's the Update Manager debug log:



This thread was automatically locked due to age.
  • Hello Kevin_Beaumont,

    please check the SUMTrace log - it might have some details.
    You've probably already read 80040410 Data read from the update source for software subscription ... was invalid. While it suggests clearing the (parent) Warehouse and Working folders when a child gives this error it's something I'd try (if the log doesn't give an insight).

    [Edit] Sorry, I didn't see the second attachment - it seems to be this .dat file ... clearing the Warehouse should reveal whether it become corrupt during transmission or not. [/Edit]

    Christian

  • Hi Christian,

    I've just tried clearing the Warehouse and Working but unfortunately the problem persists.

  • Hello Kevin,

    there are only .xml and .dat files in the Warehouse - is this the only one, which size (should be more than 100k)? Often it's a gateway that interferes - but it has worked before, so....

    Christian

  • Hi Christian,

    Any idea which file I need to identify?

    I logged a support call and tweeted support for this yesterday too but no response.  Second day without any AV updates.

  • Hello Kevin,

    the file is part of AutoUpdate, \zh_tw\alhelp.chm, size is 165327. After clearing the Warehouse is the 6bf576... there, if so - what's the size? Are there any other files with extension .dat or none? I vaguely remember cases where a gateway firewall interfered. An error on the CDN should have been detected by now.

    Christian

  • Hi Christian,

    Here's a bit from the latest log:


    2016-04-14 15:29:04 : <WARNING> Failed to retrieve time stamp from local warehouse sdds.epa_WIN2016-3.2.xml (error: Catalogue does not exist or its content is invalid: sdds.epa_WIN2016-3.2.xml)
    2016-04-14 15:29:05 : Package synchronisation started.
    2016-04-14 15:29:05 : Cmd-ALL << [I1012][6bf576554f16e0d3e1f7f78edc6fe611x000.dat] Starting to synchronise file '6bf576554f16e0d3e1f7f78edc6fe611x000.dat'...
    2016-04-14 15:29:05 : Error during package synchronisation: Checksum error: 6bf576554f16e0d3e1f7f78edc6fe611
    2016-04-14 15:29:05 : <WARNING> Sync iteration failed. CurrentResult: 4, Error: Checksum error: 6bf576554f16e0d3e1f7f78edc6fe611

    Unfortunately the checksum and filename it refers to above doesn't exist.  Nor does sdds.epa_WIN2016-3.2.xml (referenced above), just an older version, in Update Manager\Update Manager\Warehouse\catalogue folder.  The *.xml files in that folder were all modified just before we stopped getting updates, when Sophos rolled out 10.6.x to enterprise customers.

    I've no idea what to do next.

  • Ten minutes after posting this message, and this file finally downloaded:

    I can see from the trace file the download and unpacking is running now.  I'll update status when it finishes.

  • I am pleased to report after the sdds.epa_WIN2016-3.2.xml file finally magically downloaded, the updates started working again and Sophos Endpoint Control 10.6.x rolled out.