Issue ID: AV-07
Applies to: Datto AV, Datto EDR
Environment: Windows, macOS
KB Type: Troubleshooting
Overview
An Unknown value indicates that Datto EDR cannot currently determine the status of Datto AV information for the endpoint. This is typically caused by delayed reporting or a temporary communication issue and does not necessarily indicate that Datto AV protection has failed.
Symptoms
- Status displays Unknown.
- Engine Version displays Unknown or is blank.
- Signature Version displays Unknown or is blank.
- Signature Update displays Unknown or is blank.
- The endpoint may otherwise appear to be functioning normally.
Troubleshooting Steps
- Confirm which field shows Unknown:
- Status
- Engine Version
- Signature Version
- Signature Update
- Determine whether the device was:
- Recently installed
- Recently updated
- Recently rebooted
- Offline or disconnected from the network
- Allow time for normal reporting before troubleshooting further:
- Initial installation: 30-60 minutes
- After updates: 10-15 minutes
- Normal operation: 3-5 minutes
- If Signature Version or Signature Update remains Unknown after the expected reporting interval, manually initiate a Datto AV update on the endpoint.
-
Windows: Open Command Prompt as Administrator.
-
Change to the Datto EDR installation directory, and run the below command.
agent.exe datto-av --force-update - Allow the endpoint to report updated information back to the platform.
- Recheck the affected fields after the normal reporting interval.
-
-
Windows: Open Command Prompt as Administrator.
- Verify that the endpoint is online and actively communicating with Datto EDR.
- Confirm that the EDR status is “Active” in the Datto EDR portal. Resolve any network or connectivity issues before continuing.
- If the affected fields continue to show Unknown after the expected reporting interval and the endpoint is communicating normally, collect Datto agent logs for review.
- If the Unknown values continues to display after completing the steps above, open a Support ticket and provide the Datto agent logs to the Support team. For information on fetching log files, please use the following guide: Agent log files
- As a last resort, unassign and reassign the Datto AV license.
IMPORTANT: Unassigning a Datto AV license triggers a Datto AV uninstall. This process may remove information needed for troubleshooting. Collect all Datto logs before unassigning the license.
Tips and Tricks
If Unknown values appear on multiple endpoints at approximately the same time, investigate for a broader reporting, connectivity, or platform issue before troubleshooting individual devices.