This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sandstorm scan pending SMTP spool (for over a day)

Today I saw there are 3 mails in SMTP spool. Two of them are from yesterday and 1 from the day before yesterday. All 3 have status Sandstorm scan pending.
What can be wrong that these mails are still in the spool?

They look pretty legit (sender and recipient send each other more often and files and mails look like others), so I can release those mails, but that doesn't really solve the (possible) problem. Other mails have also been scanned and are delivered shortly after.



This thread was automatically locked due to age.
Parents Reply Children
  • Yes. Problem is there again since more than a week now. You have to check every day for "...sandstorm scan pending..." Mails. Sophos Support confirmed. Have to wait for a new patch. Support told me this patch will be available for 9.4 and 9.5 systems. 

  • Hi, what did the trick for us: Clear all sandbox scan pending from smtp spool. login via console. restart services sandboxd and sandbox_reportd. after that, restart sandboxd and sandbox_reoprtd again. Don´t ask why, I really don´t know, but thats how it worked for me. I see successful sandbox activity again. Maybe you only need this trick when using a cluster because at our site rolling restart of the cluster did not help. Maybe something was transferred in the switching process which caused the sandboxd and reoprtd not to fully re-initialize. So what you normally may expect from a rolling restart may not apply and that is why the manual restart of these services MAY indeed be the cure.