DLP 16.1+ Detection Server Shows 'Unknown' Status After Uninstalling a Previous Version
search cancel

DLP 16.1+ Detection Server Shows 'Unknown' Status After Uninstalling a Previous Version

book

Article ID: 388902

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

After successfully upgrading and migrating to DLP 16.1 or later, the previous version of DLP detection server was uninstalled.
After a service restart the DLP server will no longer remain connected and reports an unknown status. 

 

Environment

Upgrade to DLP 16.1 and later with DLP 16.0.1 or later uninstalled after upgrade. 

Cause

During the uninstallation shared folders are removed from the detection server that the current version of DLP relies upon. 
This includes <DataDirectory>\Symantec\DataLossPrevention\DetectionServer\Account-storage\ and subdirectories. 
DLP requires these folders for successful operation. 

 

Resolution

Uninstall has not yet been performed, or reinstall of the previous software already completed.

  • Prior to uninstall remove the delete permission from the the account-storage folder and subfolders. delete permissions should be preserved on files within the topic folders(AGENT_GROUP_ATTRIBUTE_QUERY, CRYPTO_KEY, EDM, ETC).
  • Proceed with uninstalling the older DLP version.

Uninstall has already caused the issue

  • Reinstalling the uninstalled version will replace the missing folders without the need to run the migration utility or restore settings.
  • Uninstalling and reinstalling the new version of DLP will result in migration actions being unavailable, local configurations will need to be restored manually.

 

Additional Information

If special configurations were made to the detection server prior to upgrade and migration, and the new version was uninstalled to remediate the issue, these settings will be lost and must be manually re-applied.
Enforce side data files such as scan catalogs will be reacquired.