DLP 16.1+ Detection Server Shows 'Unknown' Status After Uninstalling a Previous Version of Detection Server
search cancel

DLP 16.1+ Detection Server Shows 'Unknown' Status After Uninstalling a Previous Version of Detection Server

book

Article ID: 388902

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

After successfully upgrading and migrating to DLP 16.1 or later, the previous version of DLP detection server was uninstalled.
After a service restart the DLP server will no longer remain connected and reports an unknown status. 

 

Environment

Upgrade to DLP 16.1 and later with DLP 16.0.1 or later uninstalled after upgrade. 

Cause

During the uninstallation shared folders are removed from the detection server that the current version of DLP relies upon. 
This includes <DataDirectory>\Symantec\DataLossPrevention\DetectionServer\Account-storage\ and subdirectories. 
DLP requires these folders for successful operation. 

 

Resolution

Symantec Data Loss Prevention 16.1 hotfix 16.1.00102.60145 (Multiple Issues) released 14th of June 2025 has fix for this issue. This HF needs to be installed on top of 16.1MP1 version.

Please consider the following if the uninstall has not yet been performed or reinstall of the previous software already completed.

  • The best way to prevent this situation is to make sure the hotfix is installed for whatever version of the software being uninstalled.
    • For example if you are uninstalling 16.0.1 then you need to make sure your on 16.0.1 MP1 HF11.  If you are on 16.0.2 then you need to make sure your on HF5 for 16.0.2.  If you are on 16.1 then make sure you install MP1 HF4 at a minimum.  As long as you are on a higher hotfix version then stated above, you should be fine.   Recommendation is to make sure your on this version before the upgrade.  If you have already upgraded then you can still install the hotfix for the older release before you do the uninstall.   
  • Alternately, to uninstall remove the delete permission from the account-storage folder and subfolders. delete permissions should be preserved on files within the topic folders (AGENT_GROUP_ATTRIBUTE_QUERY, CRYPTO_KEY, EDM, ETC).
  • Proceed with uninstalling the older DLP version.

Uninstall has already caused the issue

  • Reinstalling the uninstalled version will replace the missing folders without the need to run the migration utility or restore settings.
  • Uninstalling and reinstalling the new version of DLP will result in migration actions being unavailable, local configurations will need to be restored manually.

 

Additional Information

If special configurations were made to the detection server prior to upgrade and migration, and the new version was uninstalled to remediate the issue, these settings will be lost and must be manually re-applied.
Enforce side data files such as scan catalogs will be reacquired.