Troubleshooting Sophos Linux Sensor
Troubleshoot common errors in Sophos Linux Sensor (SLS).
Licensing errors
"error": "Unauthorized" when trying to generate the SLS package registry API token.
SLS isn't available with evaluation licenses. Your Sophos Fusion account must have one of the following qualifying product licenses:
- Sophos XDR Powered by Secureworks (Server)
- Sophos MDR (Server)
- Sophos MDR Plus (Server)
I've deployed SLS sensors but my Sophos Fusion license count hasn't changed.
SLS is licensed per device. However, your Sophos Fusion Devices view and license count won't reflect your SLS instances. You also won't see your SLS devices in Server Protection. This is because SLS can send detection details and alerts to, but isn't managed by, Sophos Fusion.
Download errors
"error": "BadServerResponse" when trying to generate the SLS package registry API token.
SLS needs API credentials created by a SuperAdmin in a Sophos Fusion Admin dashboard. Ensure the configuration is done in a Sophos Fusion Admin dashboard and not in a Partner or Enterprise dashboard.
The registry 'https://packages.sophos.com/sophos-linux-sensor/release stable InRelease' is no longer signed.
Your SLS package registry API token is expired. You must generate a new token. See Generate an SLS package registry API token.
Installation errors
Invalid GPG Key from file:///etc/sophos-linux-sensor.gpg: No key found in given key data
Some distributions, such as Amazon Linux 2, require you to convert the GPG to ASCII before installing the sensor. To do this, run the following command:
gpg --keyring /etc/sophos-linux-sensor.gpg --no-default-keyring --export -a > /etc/.tmp.sophos-linux-sensor.gpg && mv /etc/.tmp.sophos-linux-sensor.gpg /etc/sophos-linux-sensor.gpg
Once you convert the GPG key, verify it again, and continue with the installation. See Verify the GPG key.
Zero policies configured
SLS default detection content isn't installed. You must install both SLS and the default content for detections and alerts to function. See Install Sophos Linux Sensor.
Event output errors
Alerts or Events not appearing in Sophos Fusion
SLS supports sending both alert and event data starting in 5.11.0. We recommend updating to 5.11 to take advantage of this setting. If you're running 5.10.0 or earlier, you can still send alert data to Sophos Fusion, but you must use the following configuration in your /etc/sophos/runtimedetections.yaml file:
alert_output:
outputs:
- type: mcs
enabled: true
url: "{MCS_URL}"
api_key: "{LINUX_REPO_API_KEY}"
Here's an example configuration file.
# This configuration sends alert data to both stdout and Sophos Fusion.
# The customer_id and api_key are redacted
send_labs_telemetry: true
endpoint_telemetry_enabled: true
cloud_meta: auto
# Set your customer id:
customer_id: "########-####-####-####-############"
alert_output:
outputs:
- type: stdout
enabled: true
template: 'Alert triggered: {{ .StrategyName}}'
- type: mcs
enabled: true
url: "https://mcs2-cloudstation-us-west-2.prod.hydra.sophos.com"
api_key: "SLS-########"
Unable to start analytics: 400 Failed to validate registration auth token on SLS startup.
SLS logs this error message and fails to start based on invalid token configurations for alert output. See Generate an SLS package registry API token.
Unable to start analytics: error writing alert to MCS on SLS startup.
SLS logs this error message and fails to start when it can't communicate with the Sophos Fusion MCS API. You must connect to the same MCS region as your Sophos Fusion account. See MCS URL.
Timed out gathering optional metadata, some optional metadata won't be available
SLS couldn't gather the optional metadata from a cloud environment. You can adjust the optional_metadata_gathering_timeout value in the runtimedetections.yaml config file to give the sensor more time to gather the optional metadata.