Skip to content

Troubleshooting Sophos Linux Sensor

Troubleshoot common errors in Sophos Linux Sensor (SLS).

Licensing errors

"error": "Unauthorized" when trying to generate the SLS package registry API token.

SLS isn't available with evaluation licenses. Your Sophos Fusion account must have one of the following qualifying product licenses:

  • Sophos XDR Powered by Secureworks (Server)
  • Sophos MDR (Server)
  • Sophos MDR Plus (Server)

I've deployed SLS sensors but my Sophos Fusion license count hasn't changed.

SLS is licensed per device. However, your Sophos Fusion Devices view and license count won't reflect your SLS instances. You also won't see your SLS devices in Server Protection. This is because SLS can send detection details and alerts to, but isn't managed by, Sophos Fusion.

Download errors

"error": "BadServerResponse" when trying to generate the SLS package registry API token.

SLS needs API credentials created by a SuperAdmin in a Sophos Fusion Admin dashboard. Ensure the configuration is done in a Sophos Fusion Admin dashboard and not in a Partner or Enterprise dashboard.

The registry 'https://packages.sophos.com/sophos-linux-sensor/release stable InRelease' is no longer signed.

Your SLS package registry API token is expired. You must generate a new token. See Generate an SLS package registry API token.

Installation errors

Invalid GPG Key from file:///etc/sophos-linux-sensor.gpg: No key found in given key data

Some distributions, such as Amazon Linux 2, require you to convert the GPG to ASCII before installing the sensor. To do this, run the following command:

gpg --keyring /etc/sophos-linux-sensor.gpg --no-default-keyring --export -a > /etc/.tmp.sophos-linux-sensor.gpg && mv /etc/.tmp.sophos-linux-sensor.gpg /etc/sophos-linux-sensor.gpg

Once you convert the GPG key, verify it again, and continue with the installation. See Verify the GPG key.

Zero policies configured

SLS default detection content isn't installed. You must install both SLS and the default content for detections and alerts to function. See Install Sophos Linux Sensor.

Event output errors

Alerts or Events not appearing in Sophos Fusion

SLS supports sending both alert and event data starting in 5.11.0. We recommend updating to 5.11 to take advantage of this setting. If you're running 5.10.0 or earlier, you can still send alert data to Sophos Fusion, but you must use the following configuration in your /etc/sophos/runtimedetections.yaml file:

alert_output:
  outputs:
  - type: mcs
    enabled: true
    url: "{MCS_URL}"
    api_key: "{LINUX_REPO_API_KEY}"

Here's an example configuration file.

# This configuration sends alert data to both stdout and Sophos Fusion.

# The customer_id and api_key are redacted

send_labs_telemetry: true
endpoint_telemetry_enabled: true
cloud_meta: auto

# Set your customer id:

customer_id: "########-####-####-####-############"
alert_output:
  outputs:
  - type: stdout
    enabled: true
    template: 'Alert triggered: {{ .StrategyName}}'
  - type: mcs
    enabled: true
    url: "https://mcs2-cloudstation-us-west-2.prod.hydra.sophos.com"
    api_key: "SLS-########"

Unable to start analytics: 400 Failed to validate registration auth token on SLS startup.

SLS logs this error message and fails to start based on invalid token configurations for alert output. See Generate an SLS package registry API token.

Unable to start analytics: error writing alert to MCS on SLS startup.

SLS logs this error message and fails to start when it can't communicate with the Sophos Fusion MCS API. You must connect to the same MCS region as your Sophos Fusion account. See MCS URL.

Timed out gathering optional metadata, some optional metadata won't be available

SLS couldn't gather the optional metadata from a cloud environment. You can adjust the optional_metadata_gathering_timeout value in the runtimedetections.yaml config file to give the sensor more time to gather the optional metadata.