Datto EDR/AV Services Stop and Cannot Be Restarted

Issue ID: EDR-07

Applies to: Datto EDR, Datto AV

Environment: Windows, macOS

KB type: Troubleshooting


Summary

This article applies when a Datto EDR or Datto AV service stops unexpectedly and cannot be restarted on a Windows or macOS endpoint. This condition may result in reduced protection or the endpoint appearing unprotected in the Datto EDR console.


Symptoms

  • Datto EDR or Datto AV service shows as Stopped in Services (Windows) or is Not Running (macOS).
  • Endpoint shows reduced or no protection status in the Datto EDR console.
  • Attempts to manually start the Datto AV service fail.
  • If Tamper Protection is enabled in the Datto EDR policy, attempts to manually start the Datto EDR agent service will also fail.

Cause

  • Service stoppage may be due to a device issue, update, or other environmental factor.
  • Manual service restarts are intentionally blocked for Datto AV, and for Datto EDR when Tamper Protection is enabled. This is by design. 
  • The Datto EDR agent monitors its own service and will attempt to restart it automatically when appropriate.

Prerequisites

  • Access to Datto RMM (if utilizing the Datto RMM/EDR integration).
  • Administrative access to the affected endpoint.

Troubleshooting Steps

To resolve this issue, complete the following steps:

  1. Reboot the Device
    • The first troubleshooting step is always to reboot the endpoint device (Windows or macOS).
  2. If utilizing the Datto RMM integration, run a job with the Datto EDR Maintenance [WIN] component.
    • Review the StdOut output from the maintenance component for errors or indications of resolution.
  3. Contact Kaseya Support
    • If the service remains stopped and cannot be started upon completion of the above steps, contact Kaseya Support
    • Collect and provide Datto EDR and AV logs from the affected endpoint. Refer to Accessing agent log files. 
    •  If utilizing the Datto RMM integration, include the job StdOut generated by the Datto EDR Maintenance [WIN[ component.

Important Notes

  • Do not configure external service monitoring: The Datto EDR agent continuously monitors its own service and automatically attempts to restart it when appropriate. Third-party service monitoring or automated restart actions are not recommended.
  • Escalate if the service does not recover: If the service remains stopped after restarting the endpoint and completing any applicable maintenance, contact Kaseya Support. There is no requirement for the issue to recur before escalating.

Service and Process Names

Windows

Datto EDR
  • Service: Datto EDR Agent service
  • Process: HUNTAgent

Datto AV

  • Services:
    • endpointProtectionService
    • endpointProtectionSecondaryService

 

macOS

Datto EDR
  • Launch daemon: HUNTAgent.plist
Datto AV
  • Process: savvy

 

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section