Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"We're checking that this computer is now safe"

Noticed that one of the machines we have is stating the message on the Sophos UI 

"We're checking that this computer is now safe. Please contact your IT administrator"

Anybody know what Sophos is actually doing here? There was no indication of a threat or malicious file found on the machine recently. Nothing stated in Sophos Central Admin Console

Recently updated to Core 2.1.2 with Endpoint Advanced 10.8.2 and Intercept X 2.0.8

The message has been there for several hours at this point



This thread was automatically locked due to age.
Parents
  • Hi Kirk Lewis,

    Are you seeing any Events on the endpoint/Central  related to isolation?
    Can you provide a screenshot of the "We're checking..." message, as well as the Events ?

    If yes to the above, I recommend that you  file a case with Support including a copy of the  SDU logs, as well as the screenshots so that they can further investigate.

    Regards,

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  •  

    Currently looking into the SDU logs option for sophos. I have been curious to know if anyone else out there has encountered this and what it might mean. 

  • It seems to me as a bit of a catch all.

    C:\Program Files\Sophos\Sophos UI\en-us.json

    Has it down as the internal names:

    "status.health.title.generic-red": "We're checking that this computer is now safe",
    "status.health.title.generic-yellow": "We're checking that this computer is now safe",

    I see you have it as yellow.  I had it once as Red due to a failed cleanup event.  Hitting the resolve link in the Events list solved it for me.

    I can only suggest looking down the list of Events for warnings and see if you find any which aren't resolved.

    Thanks,

    Jak

Reply
  • It seems to me as a bit of a catch all.

    C:\Program Files\Sophos\Sophos UI\en-us.json

    Has it down as the internal names:

    "status.health.title.generic-red": "We're checking that this computer is now safe",
    "status.health.title.generic-yellow": "We're checking that this computer is now safe",

    I see you have it as yellow.  I had it once as Red due to a failed cleanup event.  Hitting the resolve link in the Events list solved it for me.

    I can only suggest looking down the list of Events for warnings and see if you find any which aren't resolved.

    Thanks,

    Jak

Children
No Data