Completely uninstall Sophos Protection for Linux
Complete removal of Sophos Protection for Linux (SPL) has three separate parts: uninstall the agent locally with its built-in script, verify or replace the server’s protection, and only then delete an obsolete record from Sophos Fusion (formerly Sophos Central). Deleting a record in Central does not uninstall SPL from the server.
Likewise, Actions > Manage software > Uninstall current protection is not a complete local SPL uninstall: it removes protection components but leaves the Sophos Core Agent installed for communication and policy management. For complete removal, use the local uninstaller (Sophos: Computers and servers).
This procedure applies to the Sophos Protection for Linux server agent. It is not an uninstall method for Sophos Endpoint on Windows or macOS, Sophos Anti-Virus for Linux (SAV), or the separate Sophos Linux Sensor.
Process at a glance
- Confirm the maintenance window, root access, installation path and replacement protection.
- Preserve the local SPL state and required Central data.
- Run
uninstall.shfrom the installed SPL copy as root. - Use
rmdironly for the empty cgroup directories named by Sophos. - Verify local removal and active replacement protection.
- Only then delete the obsolete Central record or reinstall SPL from a current tenant installer.
Before uninstalling
- Arrange a maintenance window and monitor dependent workloads.
- Ensure root access through a root shell or
sudo. - Stop software deployment, configuration management and gold images that could reinstall SPL.
- Preserve alerts, health and investigation data before later Central deletion.
- Identify the real installation path. The default is
/opt/sophos-spl; adapt every path below for an installation made with--install-dir. - Decide how the server will remain protected. Uninstalling does not reactivate third-party security software that was removed or replaced.
Record the initial local state:
sudo systemctl status sophos-spl
sudo test -x /opt/sophos-spl/bin/uninstall.sh && printf 'SPL uninstaller found\n'
The first command may show an active service. The second must confirm an executable uninstaller. If it fails, do not copy uninstall.sh from another host or start manual file removal; establish the installation path and agent state first.
Tamper Protection and B-02: Sophos documents Tamper Protection for Windows and macOS, not for Sophos Protection for Linux. This Linux procedure therefore has no Central password and does not promise a password-free exception after licence expiry or device deletion. Do not transfer behaviour from Windows or macOS to Linux. The supported route remains the locally installed SPL uninstaller run with root rights.
Run the supported SPL uninstaller
For the default path, Sophos documents the built-in uninstaller. Run it in an administrative shell:
cd /opt/sophos-spl/bin
sudo ./uninstall.sh
For a custom installation, change to <INSTALL-BASE>/sophos-spl/bin. <INSTALL-BASE> is exactly the base supplied to --install-dir; do not transfer the script from /opt to another installation.
Preserve the exit status and complete terminal output in the change or deployment system. Process completion alone is not proof of success.
Handle remaining cgroup directories safely
Sophos specifies exactly these four commands after the uninstaller:
sudo rmdir /sys/fs/cgroup/sophos.slice
sudo rmdir /sys/fs/cgroup/cpuacct/sophos.slice
sudo rmdir /sys/fs/cgroup/cpu/sophos.slice
sudo rmdir /sys/fs/cgroup/memory/sophos.slice
rmdir removes empty directories only. A nonexistent-path message means there is nothing there to remove; absence alone does not prove a complete uninstall. Not every path applies on every distribution and cgroup version. If rmdir reports a directory is not empty or returns another unexpected error (for example, for a mounted or in-use cgroup path), preserve the exact message and state and escalate as described below. Do not continue with rm -rf, recursive wildcards or invented service, package or kernel clean-up commands.
Verify removal and replacement protection
Run at least these checks:
sudo systemctl status sophos-spl
sudo test ! -e /opt/sophos-spl/bin/uninstall.sh
sudo test ! -d /sys/fs/cgroup/sophos.slice
sudo test ! -d /sys/fs/cgroup/cpuacct/sophos.slice
sudo test ! -d /sys/fs/cgroup/cpu/sophos.slice
sudo test ! -d /sys/fs/cgroup/memory/sophos.slice
Adapt the second line for a custom installation. The sophos-spl service should no longer be active, the uninstaller should be absent from the installation path, and the named cgroup directories should be gone. The absence of individual paths that do not apply to this cgroup version is not proof of success and does not override an uninstaller failure or an unexpected rmdir error. A folder elsewhere is neither proof of active protection nor permission for manual deletion.
Also verify that the replacement product is running, current and healthy; business services and monitoring still work; no deployment job reinstalls SPL; and the host sends no new SPL activity to Central after a reasonable interval.
Only then remove the device from Sophos Fusion
For permanent retirement or replacement, clean up the record only after successful local validation. Stop before deleting any device: Check for duplicate-device warnings and other records sharing the same agent identity; a unique hostname alone is not enough. Investigate identity and cloning first, especially for cloned servers or gold images. Sophos warns that deleting a device with duplicates can prevent those devices from communicating or registering again. If a duplicate exists or identity is unclear, do not delete the device; resolve the mapping and escalate to Sophos Support (device deletion, duplicate events, Linux gold image procedure). Deregistering a gold-image template is a separate imaging procedure, not a substitute for uninstall.sh.
- Open My Environment > Computers & Servers.
- After checking for duplicates and confirming agent identity, select the unambiguously identified Linux server.
- Preserve required alerts and investigation data.
- Select Actions > Delete device and confirm deletion.
- Check that the record leaves the active list and is not recreated by a remaining or redeployed agent.
For a temporary repair or planned reinstall, do not delete the record prematurely; retain its state for diagnosis and comparison.
If uninstalling fails
uninstall.sh is missing or does not start
Recheck the path, permissions and installed SPL variant. For a custom path, the script is under sophos-spl/bin. Do not borrow scripts from another server or delete files, packages, users or services speculatively.
The service continues or SPL reports again
Review the exit status and output, then check software deployment, configuration management, startup scripts and gold images for another installation job. Do not repeatedly delete the Central record while an agent or rollout job may remain active.
A cgroup command returns an unexpected error
If a directory is not empty or rmdir returns another unexpected error, do not force recursive deletion. Capture the process and mount state, exact error, distribution, kernel, cgroup version, SPL version, installation path and time. Give these details and the uninstall.sh output to Sophos Support. Do not improvise residual clean-up commands.
Escalation point
If the agent remains active, the uninstaller fails or state is contradictory, do not mark the server as offboarded. Ensure replacement protection and, if protection is missing, isolate the server appropriately under your incident procedure. Send Sophos Support the distribution and version, architecture, kernel, SPL version, path, exact command, exit status, full output, timestamp, service status and exact cgroup error.
Only if SPL is still installed and the relevant tool is available: Optionally capture status with /opt/sophos-spl/bin/sophosctl status (Endpoint Self Help; adapt the path for a custom installation), or use the Sophos Diagnostic Utility (SDU) to collect SPL and system logs. These diagnostics are not required for a successful removal and do not replace the uninstaller log (Sophos: SPL troubleshooting).
Reinstallation and recovery
Uninstalling has no automatic rollback. To restore SPL, use a current tenant-bound Linux Server Installer from My Environment > Installers and follow Install and deploy Sophos Protection for Linux. Do not use an old installer, copied agent directory or removed uninstall.sh as a repair.
Recovery is complete only when the local service runs, the server appears in Central with the expected identity, receives the intended components and Server policies, and the required protection is demonstrably active. Keep the change open until then.