Detection Servers are in an Unknown status after applying Windows Patches
search cancel

Detection Servers are in an Unknown status after applying Windows Patches

book

Article ID: 244614

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention Enforce Data Loss Prevention Enterprise Suite

Issue/Introduction

Windows patches were applied to DLP Detection Servers and now they show as Unknown in the Enforce console

 

Cause

The SymantecDLPDetectionServer service was removed from the Services window.

The SymantecDLPDetectionServerService Registry key was deleted from the registry.

(\HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Data Loss Prevention\Services\SymantecDLPDetectionServerService)

In one case, there was a rogue script that accidentally removed the service when the Windows patch was deployed.

Resolution

Reinstall the Detection Server to ensure the service is restored.

 

Additional Information

Our recommendation to all customers is to apply the patches in a UAT/Test environment first, validate the DLP product and then install in Production with full backup and restore procedures where necessary.