Hey folks, hit a frustrating snag this week and wondering if anyone else is seeing this pattern.
We've got a handful of Windows Server 2019 VMs running the Anomali ThreatStream agent. After the latest round of Windows security updates (specifically from the November 2023 patch Tuesday), the agent service appears to be running in Services.msc, but it's completely silent. No logs are being written to its usual directory, and no data is being forwarded to the platform. The service doesn't crash or show an error state—it just... does nothing. A restart of the service temporarily fixes it, but the problem recurs within 24 hours.
What I've tried so far:
* Verified the agent process is present in Task Manager but using 0% CPU and minimal, static memory.
* Checked Windows Event Viewer and found only a generic informational event for the service start.
* Reinstalled the agent (version 5.2.1), which worked for about a day before going silent again.
* Made sure all the usual ports and outbound connectivity to the Anomali cloud are open (they are).
It feels like a permissions or a scheduling trigger issue that the update might have reset. Has anyone else run into this after recent patches? If you found a fix, I'd love to hear it—currently have to rely on a scheduled task to restart the service daily, which isn't ideal.
Ship fast, measure faster.