Sophos Central Endpoint and SEC: Computers fail/hang on boot after the Microsoft Windows April 9, 2019 update. Please follow knowledge base article 133945
Learn about the Benefits of Multi-Factor Authentication (MFA). Turn your MFA on now!
We'd love to hear about it! Click here to go to the product suggestion community
I synchronized the XG Firewall with central a couple days ago, today I notice 0 on network attacks, allowed app, blocked app, which I thought was off since we usually get something in attacks with the webserver. I then thought to check the logs and found the newest logging only shows from a few days ago which was when I turned on synchronization. Which could be a fluke of timing as well.
Has anyone had issues with logging and reporting not working correctly?
Just got off the phone with support, I was told this is a known issue and they will have to have a higher level engineer call me to deploy a patch later today.
In reply to badrobot:
There is a workaround for this. You need to disable Email Alert for Central.
In reply to LuCar Toni:
Sophos support says they don't have a solution to this problem.To temporarily resolve the situation, I put a cron job on a linux machine to restart the gartner process every hour.Here's the script for anyone who needs it.
#!/usr/bin/expect -fspawn ssh 126.96.36.199 -l adminexpect "password:"send "password\r"expect "Main Menu"send "5\r"expect "*"send "3\r"expect "*"send "service garner:restart -ds nosync\r"expect "200 OK"send "exit\r"expect "*"send "0\r"expect "*"send "0\r"
In reply to lvillarreal:
There are currently more than one issue with reporting.
One is caused by Central Heartbeat (Central integration), the other is still under investigation.
The initial Post here seems to be related to the first issue, which can be workaround by:
"Development is working on this , the work-around which we can use is "alert notifications"(Administration->Notifications settings->Alert notifications) be disabled and restart the garner."
I wrote on the wrong thread.