Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Security Heartbeat: Understanding

 Hi

I have just upgraded our Sophos Central Endpoint Standard licenses to Advanced. I can now use the security heartbeat feature of our XG 230. Yey!

However... After adding the LAN zone to be monitored suddenly half of my Windows clients reported a RED status.

On Sophos Central these PC's are showing as green, no problems. Where can I find the reason for the RED heartbeat? So I can investigate.

Thanks



This thread was automatically locked due to age.
Parents Reply
  • Hi Ben,

    I too have run into this issue numerous times, especially going from Standard to Advanced.  We have worked with Sophos support and identified an issue with the events.db file.  We have been able to fix this in 2 ways (YMMV):

    1. Remove and reinstall the client.
    2. Delete the events.db file.

    To delete the events.db file, do the following:

    1. Disable tamper protection.
    2. Navigate to C:\ProgramData\Sophos\Health\Event Store\Database\ and delete/rename events.db.
    3. Restart the Sophos Health Service and Heartbeat Service.

    Thanks,

    John

Children
  • Thanks Axsom1 that did the trick!

    I had to do it slightly different to how you have listed. There was no need to reinstall but the following worked:

    1. Disable tamper protection locally using TP password (turning it off via Central didn't do anything)

    2. Stop heartbeat service in services.msc

    3. End "Health.exe" in task manager (there is no option to stop this service in services.msc)

    4. Rename C:\ProgramData\Sophos\Health\Event Store\Database\events.db

    5. At this point there is no way to restart the Health service so i rebooted.

    Immediately the Status of this PC turned green on the XG console!

    Cheers