Skip to content
Avanet

Synchronized Application Control: Safely Check Database Issues

If Synchronized Application Control stops detecting new applications, heartbeatd.log reports errors, or a firewall is critically low on storage after an upgrade, the internal application database may be affected. However, this is not a case for generic PostgreSQL commands from a forum or an old support note.

Sophos Firewall manages this data internally. Since SFOS 20.0 MR1, it limits occurrences per application and endpoint; SFOS 21.0 and later also provide configurable age-based cleanup. This article explains how to set normal retention, safely narrow down an issue, and manage any required support intervention in a controlled manner.

Classify the Problem Correctly

Synchronized Application Control uses information from endpoints connected to the firewall through Security Heartbeat. This allows the firewall to identify applications that conventional signatures cannot classify unambiguously and makes them available for management under Applications > Synchronized Application Control.

These terms should not be confused:

  • Security Heartbeat communicates health and security status between the endpoint, firewall, and Sophos Fusion (formerly Sophos Central).
  • Synchronized Application Control records applications and where they were detected on connected endpoints.
  • Missing heartbeat describes a missing endpoint status and can be managed using supported Device Console commands.
  • An app ID or database issue affects the internal storage of detected applications and requires separate diagnosis.

A missing heartbeat indicator, a red endpoint, or a mismatched firewall rule therefore does not automatically indicate a database issue. To troubleshoot the connection between the firewall and Sophos Fusion, start with Connect Sophos Firewall to Sophos Fusion.

Understand Retention and Cleanup

Two important product rules apply to Synchronized Application Control:

  • Synchronized Application Control supports up to 15,000 applications.
  • Since SFOS 20.0 MR1, the firewall stores only the five most recent occurrences of each application per endpoint.

When migrating to SFOS 20.0 MR1 or later, the firewall retains the five most recent occurrences and automatically removes older occurrence data. However, Sophos notes that this migration cleanup may fail when there is insufficient free storage. In this case, contact Sophos Support.

Separately, SFOS can delete applications whose last detection is older than the configured retention period. The firewall checks for them daily and deletes batches of 100 every five minutes. Applications added individually to Application Filters are removed from those filters as well.

When you migrate to SFOS 21.0 or later with Synchronized Application Control turned on, Clean up application database is enabled with the default retention period of 12 months. A previously customized period is retained. Turning off Synchronized Application Control also turns off cleanup.

This distinction is important: configure supported age-based retention in the interface. Direct database maintenance remains outside routine administration.

Configure Routine Cleanup

The firewall must be registered with Sophos Fusion and have a valid Web Protection subscription. You can configure Synchronized Application Control without that subscription, but you cannot use it. The domain created on the firewall must also match the domain selected on the endpoint.

  1. Go to System > Sophos Fusion and confirm that the firewall is registered and Synchronized Application Control is turned on.
  2. Turn on Clean up application database.
  3. Choose the retention period. 12 months is the migration default and a sensible starting point if you have no specific policy. A shorter period reduces stale entries sooner, but also removes individually assigned applications from Application Filters sooner.
  4. Save the setting and monitor the inventory over the next daily cleanup runs.

Cleanup is deliberately gradual. An unchanged count immediately after saving is therefore not a failure. For validation, compare the oldest visible detection time and the number of old applications before and after at least one daily run; new applications must continue to appear.

⚠️ Turning cleanup off stops future deletions, but does not restore applications or filter assignments already removed. A detected application will reappear in the list, but you must add it back to an Application Filter if required.

Distinguish Typical Symptoms

Storage Issue After an Upgrade or Cleanup

Possible indicators include a heavily used partition, failed reports or services, and a correlation with an upgrade or an age-based cleanup that is not progressing. This alone does not prove that Synchronized Application Control is the cause.

First check reports, debug logs, support archives, the mail queue, quarantine, and the size of a virtual disk. The process is described in Check Sophos Firewall Storage and Manage Reports.

App ID Range Exhausted

Another symptom is a message such as:

Cannot create ID for application, because appId range is exhausted.
Application will be ignored.

The firewall may continue to display existing applications but can no longer reliably record new ones. This message points to Synchronized Application Control, not to a general report or log database issue.

A list approaching the product limit of 15,000 applications indicates a Synchronized Application Control capacity issue. A full partition is a separate storage issue. The two symptoms can occur together, but neither proves the cause of the other, so investigate them separately.

Security Heartbeat Is Not Working

If endpoints do not report a heartbeat status or rules with heartbeat conditions do not work as expected, first check Sophos Fusion registration, endpoint communication, the affected zones, and the firewall rule. Direct database cleanup is not the correct approach for this issue.

Diagnosis Before Opening a Support Case

1. Document the Firmware and Context

Include the following information in the case notes:

  • Firewall model, serial number, and complete SFOS version including the build
  • Standalone, HA Primary, or HA Auxiliary
  • Date of the most recent upgrade and the previous SFOS version
  • Time from which the issue became visible
  • Affected services and the specific impact

In HA, it must be clear which node is showing the symptom. Local logs and storage usage can differ between the Primary and Auxiliary.

2. Check the Application View

Under Applications > Synchronized Application Control, check:

  • Are new applications still being detected?
  • Is the list approaching the limit of 15,000 applications?
  • Does the issue affect only new applications or existing entries as well?
  • Can applications be searched, opened, and managed?
  • Are deleted applications recreated as expected after being detected again?

Deleting individual applications in the interface is a supported function, but it also removes them from Application Filters. If the firewall detects the application again, it reappears. This UI function is therefore not a database repair.

3. Check the Storage Situation Separately

Document storage usage before taking further action. Record the affected partition and the change over time, not just a single percentage value.

If reports, logs, or support archives are deleted at the same time, it will no longer be possible to determine which measure actually helped. Collect evidence first, then make only one change at a time.

4. Collect Logs and the Troubleshooting Report

For Synchronized Application Control and Security Heartbeat, heartbeatd.log is particularly relevant. Also record the exact time of the error and collect a troubleshooting report.

The relevant files and collection methods are described in Sophos Firewall Troubleshooting: Services and Logs and Save Sophos Firewall Logs for External Analysis.

Do Not Adopt Public Database Commands

Various psql, DELETE, VACUUM FULL, and service restart commands for older SFOS versions and different heartbeat issues circulate online. These procedures are not interchangeable:

  • A VACUUM FULL frees storage used by a table but does not automatically remove the cause of its growth.
  • A DELETE can alter associations between applications, endpoints, or currently authenticated users.
  • Tables and support procedures can differ between SFOS versions.
  • In HA, the procedure also depends on the node, synchronisation status, and support instructions.

⚠️ Do not make direct changes to the internal PostgreSQL database without current, case-specific instructions from Sophos Support. A configuration backup is important, but it does not provide a complete rollback of the internal database.

Commands from a previous ticket should likewise not be applied to another firewall, firmware version, or HA role without verification. The exact instructions must be included in the current support case and specify the affected node and expected result.

Prepare a Complete Support Case

A well-prepared case accelerates analysis and prevents follow-up questions. Include:

  • Complete SFOS version and firewall model
  • Serial number and HA role of the affected node
  • Time and exact wording of the error message
  • Screenshot of Applications > Synchronized Application Control
  • Storage usage before any cleanup performed by the administrator
  • heartbeatd.log and a troubleshooting report for the relevant period
  • Date and path of the most recent firmware upgrade
  • Description of whether new applications are missing, storage is low, or both conditions occur

Before a support intervention, make sure a current firewall configuration backup is available. Open a Sophos Support Ticket explains how to create the case.

If support instructs you to perform a database intervention, record the ticket number, approved commands, target node, maintenance window, expected output, and abort criteria in the change. Document and report unexpected error messages instead of experimenting with similar commands.

Verify the System After the Support Action

After the approved action, free storage or successful command output alone is not sufficient. Verify the complete functional path:

  1. Open Applications > Synchronized Application Control and check the existing entries.
  2. Start a new application that has not previously been detected on a test endpoint.
  3. Check whether the application appears and can be managed.
  4. Check the Security Heartbeat status of the test endpoint.
  5. Test firewall rules with heartbeat or Application Control conditions.
  6. Check heartbeatd.log for new errors during the test period.
  7. Monitor storage usage over several hours or days.

If the error or growth returns quickly, the cleanup provided only temporary relief. Sophos Support will then need the new timeline, current logs, and information about which action preceded the recurrence.

FAQ

Should the Synchronized Application Control database be cleaned regularly?

Yes, but only through Clean up application database under System > Sophos Fusion. From SFOS 21.0, this supported age-based cleanup defaults to 12 months after migration when Synchronized Application Control is on. Direct PostgreSQL maintenance remains a support task.

What does appId range is exhausted mean?

The firewall cannot create a new internal ID for a detected application and ignores that application. Investigate this Synchronized Application Control issue using the application view, heartbeatd.log, firmware version, and Sophos Support.

Can old psql commands from the Sophos Community be used?

Not without current approval from Sophos Support. Public commands may be intended for a different SFOS version, issue, or HA node and can alter application, endpoint, or user associations.

Is a configuration backup sufficient as a rollback method?

No. A configuration backup is important before maintenance work, but it does not provide a complete rollback for direct changes to the internal PostgreSQL database. The recovery process must therefore be part of the support instructions.