<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Endpoint Service Stopped in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649879#M6977</link>
    <description>&lt;P&gt;You should see it under Program Files &amp;gt; Cisco &amp;gt; AMP. However, I forgot to mention earlier that there's a setting that'll determine if the dump will be written and saved locally or sent to the cloud. This setting, called "Automatic Crash Dump Uploads", can be found under Policy &amp;gt; Advanced Settings &amp;gt; Administrative Features. The "Connector Log Level" will also be in the same page so I recommend setting the log level to Debug then disabling the Automated Crash Dump Upload and see if there's a .dmp file created under the AMP directory once the issue reoccurs.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 21:31:06 GMT</pubDate>
    <dc:creator>DaphneG</dc:creator>
    <dc:date>2022-07-13T21:31:06Z</dc:date>
    <item>
      <title>Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4636014#M6932</link>
      <description>&lt;P&gt;Good day all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From time to time, I find that there are several of our machines that have their service stopped with Secure Endpoint. I haven't found what has been stopping it, but has anyone seen this and know what has been causing this? And is there a way to detect machines whose service has been stopped from the console?&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;Maurice&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4636014#M6932</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-06-21T16:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4643465#M6941</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you mean from time to time you find 'Cisco Secure Endpoint' service was in a 'stopped' status?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you ticked the checkbox of 'enable connector protection'? you can find this option under 'advanced settings' -&amp;gt; 'administrative features' of your policy.&lt;/P&gt;
&lt;P&gt;This feature can prevent&amp;nbsp; malware, application or user from disabling secure endpoint service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 15:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4643465#M6941</guid>
      <dc:creator>JennieZhang</dc:creator>
      <dc:date>2022-07-04T15:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4644614#M6943</link>
      <description>&lt;P&gt;Hey Jennie! Thanks for responding. Yes, that's exactly what I mean on the services being stopped. I've found a few machines in the environment where it was stopped and it wasn't in positioned to be scanned or anything. In regards to your question about the connector protection, yes, we do have that turned on as well. I'm not sure if there's anything that's stopping it outside of that or if anyone has experienced this happening consistently. Outside of having people open CSE on their computers, I'm not sure if there's a way to check from the console if the services have stopped.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 21:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4644614#M6943</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-07-05T21:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649606#M6970</link>
      <description>&lt;P&gt;Is there any update on this?&amp;nbsp; We have the same issue, to the tune of 25% of our systems at a time.&amp;nbsp; And having to connect to EACH one just to restart the service is a time killer.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 15:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649606#M6970</guid>
      <dc:creator>newberntac</dc:creator>
      <dc:date>2022-07-13T15:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649715#M6971</link>
      <description>&lt;P&gt;Hey! Unfortunately, the closest solution that has been recommended was the connector protection. Unfortunately, that doesn't keep the connector services from stopping. I'm still not sure what is happening to cause the service to stop, but it's something I'd like to get to the bottom of to make sure that our environment is secured.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 17:30:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649715#M6971</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-07-13T17:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649805#M6972</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1311413"&gt;@mandrews&lt;/a&gt;, I suggest checking the Secure Endpoint directory for crash dumps then opening a TAC case. If you have an open SR, feel free to PM me the number so I can review/follow up with the TAC engineer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 19:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649805#M6972</guid>
      <dc:creator>DaphneG</dc:creator>
      <dc:date>2022-07-13T19:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649857#M6974</link>
      <description>&lt;P&gt;Hey Daphne!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Do you know the file path or the file name for the file that would have the crash dump? I'm assuming that it would be a temp file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 19:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649857#M6974</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-07-13T19:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649863#M6975</link>
      <description>&lt;P&gt;I found this on setting the client up to collect debug info.&amp;nbsp; We're going to try and gather debugs too.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/216035-collect-debug-logs-file-in-amp-for-endpo.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/216035-collect-debug-logs-file-in-amp-for-endpo.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 20:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649863#M6975</guid>
      <dc:creator>newberntac</dc:creator>
      <dc:date>2022-07-13T20:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649875#M6976</link>
      <description>&lt;P&gt;I normally use debugs when CSE is using a lot of CPU utilization from scanning. I don't know if it'll reveal what is kicking off the connector, unless it scanning something too much is what stops the service.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 21:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649875#M6976</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-07-13T21:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649879#M6977</link>
      <description>&lt;P&gt;You should see it under Program Files &amp;gt; Cisco &amp;gt; AMP. However, I forgot to mention earlier that there's a setting that'll determine if the dump will be written and saved locally or sent to the cloud. This setting, called "Automatic Crash Dump Uploads", can be found under Policy &amp;gt; Advanced Settings &amp;gt; Administrative Features. The "Connector Log Level" will also be in the same page so I recommend setting the log level to Debug then disabling the Automated Crash Dump Upload and see if there's a .dmp file created under the AMP directory once the issue reoccurs.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 21:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649879#M6977</guid>
      <dc:creator>DaphneG</dc:creator>
      <dc:date>2022-07-13T21:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649930#M6978</link>
      <description>&lt;P&gt;With the debugging enabled, it provides us more context and enables us to correlate things with the dump.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Btw, if after following the recommendations below you're still not seeing any .dmp files, please open a TAC case and use this discussion as reference.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 23:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4649930#M6978</guid>
      <dc:creator>DaphneG</dc:creator>
      <dc:date>2022-07-13T23:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4650493#M6981</link>
      <description>&lt;P&gt;That feature makes sense now. Assuming that we have crash dump logs sent to the cloud, do our organization have access to that? Also, is there a way to detect a stopped service with CSE from the console?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 17:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4650493#M6981</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-07-14T17:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4683024#M7077</link>
      <description>&lt;P&gt;Hello Maurice,&lt;/P&gt;
&lt;P&gt;I wanted to know if you were able to file a TAC Case for this issue so that we can investigate this issue further.&lt;/P&gt;
&lt;P&gt;To answer your queries above:&lt;/P&gt;
&lt;P&gt;1) No, unfortunately, these logs(Crash Dumps) are not to the customers&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) You should be able to detect stopped services on the endpoint using Orbital as a probe. On the portal, the "Last Seen" Date would be the only indicator to help you detect stopped service on the Endpoints.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Vibhor&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 18:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4683024#M7077</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2022-09-07T18:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4691660#M7096</link>
      <description>&lt;P&gt;Hey Vibhor!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I haven't opened a TAC case for this yet. I haven't spotted any lately, but maybe your suggestion using Orbital may help. What query can I use to detect the stopped CSE service? If that returns any results, then I'll use that evidence and submit a TAC case with it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 21:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4691660#M7096</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2022-09-21T21:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4691668#M7097</link>
      <description>&lt;P&gt;To further add on Vibhor's reply, you can also use Powershell to get a list of Services and their status&lt;/P&gt;
&lt;P&gt;Get-Service -Name Cisco* | ft -auto &lt;/P&gt;
&lt;P&gt;If you want the results in a txt file, please use Get-Service -Name Cisco* | ft -auto | Out-File "C:\Users\insertusernamehere\Desktop\cisco.txt"&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 22:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4691668#M7097</guid>
      <dc:creator>UMontero</dc:creator>
      <dc:date>2022-09-21T22:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4753971#M7238</link>
      <description>&lt;P&gt;Any update on this? We are seeing similar things. In December we noticed the service was stopped on a bunch of (Windows) servers. Services seemed to never have started after an automatic server restart (windows update) and we only noticed because we have monitoring of services on this particular customers servers. So it really stood out on our monitoring-dashboard that the services were not running on all these servers.&lt;/P&gt;
&lt;P&gt;A few days ago, another customer also noted stopped AMP services on some of his servers and also on some Windows clients.&lt;/P&gt;
&lt;P&gt;Both customers are running v. 7.5.x. Maybe version 8 is better?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 22:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4753971#M7238</guid>
      <dc:creator>joljol</dc:creator>
      <dc:date>2023-01-12T22:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4754514#M7239</link>
      <description>&lt;P&gt;Not really. I haven't been discovering many stopped services anymore. It helps to audit the console every month or so to see if there are computers consistently not being seen for over a week or a month. The script that was mentioned earlier in the thread is helpful if you can find a way to run it across your network. We have been updating our versions, so maybe it was the 7.5.5 version that wasn't performing. Either way, if I stumble across something else, then I'll let you know.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 21:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4754514#M7239</guid>
      <dc:creator>mandrews</dc:creator>
      <dc:date>2023-01-13T21:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4755606#M7257</link>
      <description>&lt;P&gt;Thank you for replying. I will try and convince our customer to update to version 8 of the connector, and instruct him on how to setup and gather debug logs, in case it happens again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 19:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4755606#M7257</guid>
      <dc:creator>joljol</dc:creator>
      <dc:date>2023-01-16T19:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4756113#M7258</link>
      <description>&lt;P&gt;Well I found a clue to why Cisco Secure Endpoint is periodically stopped or disabled.&amp;nbsp; In the system event logs, I found both the CSE service and its companion service, Cisco SCMS, failed to start after a system reboot, because the network service hadnt started yet (really? &amp;lt;anger emoji&amp;gt;):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Event# 7009, Source: Service Control Manager:&amp;nbsp; A timeout was reached (30000 milliseconds) while waiting for the CiscoAMP service to connect.&lt;/LI&gt;&lt;LI&gt;Event# 7000, Source: Service Control Manager:&amp;nbsp; The CiscoAMP service failed to start due to the following error:&amp;nbsp; The service did not respond to the start or control request in a timely fashion.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Event# 7009, Source: Service Control Manager:&amp;nbsp; A timeout was reached (30000 milliseconds) while waiting for the CiscoSCMS service to connect.&lt;/LI&gt;&lt;LI&gt;Event# 7000, Source: Service Control Manager:&amp;nbsp; The CiscoSCMS service failed to start due to the following error:&amp;nbsp; The service did not respond to the start or control request in a timely fashion.&lt;OL&gt;&lt;LI&gt;Eight seconds later, the network starts.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Event# 7036, Source: Service Control Manager:&amp;nbsp; The Network Setup Service service entered the running state.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Not gonna lie, this is maddening.&amp;nbsp; Isnt the whole point of the Cisco SCMS (Security Connector Monitoring Service) to identify when the service is down and restart it?&amp;nbsp; &amp;nbsp;(and look at that, the Crowdstrike rep is calling me again.)&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 17:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4756113#M7258</guid>
      <dc:creator>crockbot</dc:creator>
      <dc:date>2023-01-17T17:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint Service Stopped</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4756116#M7259</link>
      <description>&lt;P&gt;Well I found a clue to why Cisco Secure Endpoint is periodically stopped or disabled.&amp;nbsp; In the system event logs, I found both the CSE service and its companion service, Cisco SCMS, failed to start after a system reboot, because the network service hadnt started yet (really? &amp;lt;anger emoji&amp;gt;):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Event# 7009, Source: Service Control Manager:&amp;nbsp; A timeout was reached (30000 milliseconds) while waiting for the CiscoAMP service to connect.&lt;/LI&gt;&lt;LI&gt;Event# 7000, Source: Service Control Manager:&amp;nbsp; The CiscoAMP service failed to start due to the following error:&amp;nbsp; The service did not respond to the start or control request in a timely fashion.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Event# 7009, Source: Service Control Manager:&amp;nbsp; A timeout was reached (30000 milliseconds) while waiting for the CiscoSCMS service to connect.&lt;/LI&gt;&lt;LI&gt;Event# 7000, Source: Service Control Manager:&amp;nbsp; The CiscoSCMS service failed to start due to the following error:&amp;nbsp; The service did not respond to the start or control request in a timely fashion.&lt;OL&gt;&lt;LI&gt;Eight seconds later, the network starts.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Event# 7036, Source: Service Control Manager:&amp;nbsp; The Network Setup Service service entered the running state.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 17 Jan 2023 17:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-service-stopped/m-p/4756116#M7259</guid>
      <dc:creator>crockbot</dc:creator>
      <dc:date>2023-01-17T17:13:03Z</dc:date>
    </item>
  </channel>
</rss>

