A large number of agents are failing to update anti-malware database. A majority of the agents do update. They are all on the same network, behind the same firewall with the same policy, same agent version. The GUI says Anti-Malware Database failed. No connection to servers. In the AntiMalwareBlade log, we see the following:
2020-10-22 01:31:47.678 t:44800 epam [info ] EP_EVENT_UPDATE_PROGRESS: download progress=92% [AntiMalware::Updater::Updater::HandleUpdaterEvent]
2020-10-22 01:31:47.698 t:44800 EiKav [info ] kuDoDownload returned: Result: 1c (SDK_CORE_DOWNLOAD_ERROR) [AMEngine::Kav::KavUpdater::Update]
2020-10-22 01:31:47.698 t:44800 epam [info ] Sending message, UPDATE_FAILED, engine returned result: 0x1c [AntiMalware::Updater::Updater::HandleUpdaterEvent]
2020-10-22 01:31:47.698 t:44800 epam [error] Failed getting updates or canceled [AntiMalware::Updater::Updater::UpdaterThread]
2020-10-22 01:31:47.698 t:44800 EiKav [info ] Updater SDK unloaded successfully [AMEngine::Kav::KavUpdater::UnloadUpdaterSDK]
2020-10-22 01:31:47.702 t:604 epam [info ] Update result is UCR_SERVER_NOT_AVAILABLE(0) [AntiMalware::Adaptors::EpamUiProxy::HandleUpdateCompleted]
2020-10-22 01:31:47.702 t:604 epam [error] UI translated updateResult result is 3 [AntiMalware::Adaptors::EpamUiProxy::HandleUpdateCompleted]
2020-10-22 01:31:47.702 t:5796 epam [info ] Update operation finished, result UCR_SERVER_NOT_AVAILABLE(0) [AntiMalware::Updater::Updater::HandleNotifyUpdateCompletedMsg]
2020-10-22 01:31:47.708 t:4696 EiKav [info ] DatVersion is: 202007140911 [AMEngine::Kav::KavProtectionEngine::GetDatVersionInternal]
2020-10-22 01:31:47.708 t:4696 EiKav [info ] DatVersion is: 202007140911 [AMEngine::Kav::KavProtectionEngine::GetDatVersionInternal]
2020-10-22 01:31:47.709 t:8148 epam [info ] Updated EngineVersion is '8.9.2.1183' and signatures version is = '202007140911' [AntiMalware::EpamDafDaAdaptor::DafDaProxy::HandleUpdateCompleted]
2020-10-22 01:31:47.709 t:8148 epam [info ] Sending log event string (31 separators): '1310764Anti-MalwareConnected01603309536v18 - Anti-Malware (1)12020071409118.9.2.1183ErrorServer Not Available' [AntiMalware::EpamDafDaAdaptor::DafDaProxy::SendLogEvent]
2020-10-22 01:31:47.714 t:5796 epam [info ] immediate update required, engine is already initialized. Starting update in 15 minutes [AntiMalware::Updater::Updater::SetScheduledUpdateAlarm]
2020-10-22 01:31:47.715 t:5796 epam [info ] Last update: 1969-Dec-31 20:00:00; calculated next scheduled update: 2020-Oct-22 01:46:47; timesSkipped: 111343 [AntiMalware::Updater::Updater::SetScheduledUpdateAlarm]
2020-10-22 01:31:47.716 t:5796 epam [info ] Sent current update tasks status: {TaskName = Update, LastSucceededTime = 0(1970-Jan-01 00:00:00), LastAttemptTime = 1603344689(2020-Oct-22 05:31:29), NextScheduledTime = 1603345607(2020-Oct-22 05:46:47)} [AntiMalware::Updater::Updater::UpdateSystemTasksRecord]
2020-10-22 01:31:47.716 t:5796 epam [info ] SetAlarmTaskMsg sent with flowUid = 000000000000180c:0000000000021c64 [AntiMalware::Updater::Updater::SetScheduledUpdateAlarm]
2020-10-22 01:31:47.738 t:5796 epam [info ] Sent current update tasks status: {TaskName = Update, LastSucceededTime = 0(1970-Jan-01 00:00:00), LastAttemptTime = 1603344689(2020-Oct-22 05:31:29), NextScheduledTime = 1603345607(2020-Oct-22 05:46:47)} [AntiMalware::Updater::Updater::HandleGetSystemTaskStatusMsg]
2020-10-22 01:31:47.738 t:4696 EiKav [info ] DatVersion is: 202007140911 [AMEngine::Kav::KavProtectionEngine::GetDatVersionInternal]
2020-10-22 01:31:47.740 t:4696 EiKav [info ] DatVersion is: 202007140911 [AMEngine::Kav::KavProtectionEngine::GetDatVersionInternal]
2020-10-22 01:31:47.796 t:5956 epam [info ] Uploading record: {ProtocolVersion = <no_value>, ClientVersion = <no_value>, Type = 102020, ListFiles = <no_value>, MetaData1 = <no_value>, MetaData2 = <no_value>, IntField1 = <no_value>, IntField2 = <no_value>, IntField3 = <no_value>, IntField4 = <no_value>, IntField5 = <no_value>, IntField6 = <no_value>, IntField7 = <no_value>, IntField8 = <no_value>, IntField9 = <no_value>, IntField10 = <no_value>, StrField1 = <no_value>, StrField2 = <no_value>, StrField3 = <no_value>, StrField4 = {"Severity":"Critical","Product":"Anti-Malware","ConnectivityState":"Connected","Result":"Error","UpdateSource":"","UpdateProxy":"","UpdateVersion":"202007140911","EngineVersion":"8.9.2.1183","Details":"Server Not Available"}, StrField5 = CK-F2FCCA3C47DB, StrField6 = <no_value>, StrField7 = <no_value>, StrField8 = <no_value>, StrField9 = <no_value>, StrField10 = <no_value>} [AntiMalware::ThreatCloud::ThreatCloud::SendTMUpdate]
Any ideas?
Thanks!