This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[SFOS 18.5MR3] Poor spam detection after update to Sophos Anti-Spam Interface

Hi everyone,
I am setting up a separate thread as I did not receive any specific reply in other threads.

The case concerns Sophos Anti-Spam Interface after upgrading from v18.5MR2 to v18.5MR3 and from v19EAP1 to v19EAP2.

Before updating, antispam works great in legacy mode, detects a lot of intrusive messages and tags with a prefix (near 99%). After updating, only some messages are detected as spam and tagged (I did not do any changes in configuration).

What it comes from? How can I edit my lists to achieve pre-update spam detection?

Greetings



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Emmanuel,

    the u2d.log is 34mb, there are no entries in EML with the X-SASI-*. I checked valid and spam messages. Both logs files you have requested are dated  at 0850 this morning.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Emmanuel,

    Do you still want copies of the files even though there is no X-SASI-* in the EMLs? Or do I wait until v19 has been released as GA?

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Helo rfcat,

    Thank you for the follow-up.

    Yes, and if you have any other emails coming since 3 days ago that are SPAM. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • I have spam mail, but they do not contain any X-SASI entries.

    I will capture the files and forward them to you.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Emmanuel,

    have sent you the requested files in two PMs

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, any news about investigation? I had reverted to MR2, because spam tags are very useful for me.

  • Since the update on March 31, 2022, the following error messages have appeared in the log.

    SFV2C4MSP_VM01_SFOS 18.5.3 MR-3-Build408# cat /log/sasi.log | grep ERROR
    2022-03-31.22:33:57 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.02:18:08 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.05:22:14 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.06:40:46 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.07:16:21 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.07:18:28 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.08:44:49 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:08:14 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:11:09 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:16:40 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.09:54:54 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.10:40:28 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:49:19 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:56:02 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.11:57:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.13:06:41 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.13:42:38 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.13:59:26 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.14:55:23 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.15:30:50 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.16:45:15 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.16:57:17 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.16:58:40 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:42:26 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:43:47 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.18:45:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.22:11:54 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.22:13:13 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.04:54:28 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.07:38:46 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.08:51:51 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:31:53 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-02.12:02:01 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-02.13:56:08 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:00:20 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:40:21 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.23:24:32 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-03.08:13:06 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.12:08:41 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.12:13:15 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.12:25:25 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.12:26:40 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.13:28:23 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.14:07:27 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.14:37:20 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.14:45:42 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.15:17:22 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.20:20:58 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-03.21:01:37 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.21:41:38 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.22:21:39 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-03.23:01:40 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.00:45:45 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.06:29:55 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.07:09:56 ERROR    [Main] [          precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.08:19:45 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.08:30:05 ERROR    [Main] [          precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.09:39:37 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:09:08 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:13:38 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.10:42:33 ERROR    [   2] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.11:04:32 ERROR    [   3] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.11:18:15 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.14:07:38 ERROR    [   1] [         DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.15:13:15 ERROR    [   0] [         DNS/Request.cpp:246] vector::_M_range_check
    SFV2C4MSP_VM01_SFOS 18.5.3 MR-3-Build408#

  • got these errors:

    SFVH_SO01_SFOS 18.5.3 MR-3-Build408# cat /log/sasi.log | grep ERROR
    2021-12-07.23:34:07 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: downloads.sophos.com/.../asdb.antispam.old.csum
    2021-12-07.23:50:08 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: downloads.sophos.com/.../asdb.antispam.old.csum
    2021-12-08.13:27:57 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-08.13:34:08 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-09.13:44:09 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2021-12-09.14:24:13 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2021-12-09.20:48:36 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-09.21:28:39 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-10.14:24:46 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-11.00:50:11 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2021-12-11.05:07:22 ERROR [ 1] [ DNS/Request.cpp:246] vector::_M_range_check
    2021-12-11.20:27:13 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-24.21:09:45 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-24.22:29:50 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.01:58:04 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2022-03-25.04:14:18 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.06:38:33 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.07:18:32 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-25.08:14:38 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.13:55:49 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-25.21:11:39 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-25.22:31:45 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.02:16:02 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.08:00:35 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.13:04:54 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-26.13:44:56 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.00:33:44 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.17:50:59 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.18:31:02 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-27.20:31:10 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-28.04:39:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.07:20:00 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.11:44:20 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-28.23:53:15 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.09:21:58 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-29.13:06:17 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.18:50:54 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.19:30:57 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-29.20:25:14 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-29.21:31:05 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-29.23:55:16 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-30.06:59:49 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-30.18:18:03 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-31.02:46:11 ERROR [ 0] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-03-31.08:45:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.09:25:51 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.10:05:52 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-03-31.17:10:25 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-03-31.21:26:53 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-04-01.01:59:06 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.11:27:48 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-01.18:32:23 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-01.23:44:46 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:13:30 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.09:53:31 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-02.16:58:05 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.17:38:07 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.18:18:10 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-02.19:22:13 ERROR [Main] [ precompile.cpp:715] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.delta
    2022-04-02.22:42:31 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.00:18:51 ERROR [Main] [ precompile.cpp:661] Couldn't fetch: sasi.sophosupd.com/.../asdb.antispam.old.csum
    2022-04-03.22:20:20 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-03.22:44:20 ERROR [Main] [ precompile.cpp:724] Precompile exception: Failed to apply delta to signatures.
    2022-04-04.04:28:48 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.05:35:33 ERROR [ 2] [ DNS/Request.cpp:246] vector::_M_range_check
    2022-04-04.13:57:32 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.17:40:29 ERROR [Main] [ precompile.cpp:697] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    SFVH_SO01_SFOS 18.5.3 MR-3-Build408#

    Bart van der Horst


    Sophos XG v18(.5) / v19 Certified Architect
    https://www.bpaz.nl

  • 2022-04-04.18:20:31 ERROR [Main] [ precompile.cpp:647] Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.tmp
    2022-04-04.18:21:22 ERROR [Main] [ laseserver.cpp:159] Couldn't fetch new signatures: Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.antispam Exiting..

    Bart van der Horst


    Sophos XG v18(.5) / v19 Certified Architect
    https://www.bpaz.nl

  • SFVH_SO01_SFOS 18.5.3 MR-3-Build408# tail /log/sasi.log -F
    Failed to run server: Couldn't fetch new signatures: Downloaded file could not be verified with checksum. Discarding /sdisk/sasi/asdb.antispam Exiting..
    2022-04-04.18:26:38 MESSAGE [Main] [ main.cpp:78] LASE Daemon STARTED
    2022-04-04.18:26:38 MESSAGE [Main] [ main.cpp:80] LASE Daemon Version: 4.1.4
    2022-04-04.18:26:38 MESSAGE [Main] [ laseserver.cpp:372] Lased started on port : 25315
    2022-04-04.18:27:42 MESSAGE [Main] [ main.cpp:78] LASE Daemon STARTED
    2022-04-04.18:27:42 MESSAGE [Main] [ main.cpp:80] LASE Daemon Version: 4.1.4
    2022-04-04.18:27:42 MESSAGE [Main] [ engine.cpp:306] Signatures don't exist, fetching new signatures..
    2022-04-04.18:27:44 MESSAGE [Main] [ precompile.cpp:580] Downloaded file /sdisk/sasi/asdb.antispam is verified with checksum..
    2022-04-04.18:27:44 MESSAGE [Main] [ engine.cpp:362] New signatures are downloaded and validated.
    2022-04-04.18:27:44 MESSAGE [Main] [ laseserver.cpp:372] Lased started on port : 25315

    I deleted all files in the /sdisk/sasi dir and restarted the antispam service

    No he says the correct asdb.antispam is loaded

    Bart van der Horst


    Sophos XG v18(.5) / v19 Certified Architect
    https://www.bpaz.nl