PowerScale: CAVA Service Down After Upgrading CEE

Summary: Upon upgrading the Common Event Enabler (CEE) Software to 9.0.0.0 or later, the Common Anti-Virus Agent (CAVA) service goes to a faulted state in OneFS. This may also affect auditing to Varonis or other third-party auditing software. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Symptom on Windows:

Microsoft Windows [Version 10.0.17763.920]
(c) 2018 Microsoft Corporation. All rights reserved.
C:\Windows\system32>netstat -an | find "12228"
C:\Windows\system32>

Error in Windows event logs:

CAVA has detected that the CAVASAV Agent has not been loaded or started. CAVA cannot process AV requests until the CAVASAV Agent is started

CAVA has detected that either there is no third party antivirus software installed or that the resident antivirus software, if any, has not been started. CAVA cannot process AV requests until the appropriate antivirus software is installed and started

Cause

HTTP Service was not selected during installation.

Resolution

Starting with CEE 9.0.0, secure defaults are on by default, so two extra steps are required during installation:

  1. Enable HTTP - HTTP is disabled by default in CEE 9.x. It must be turned on during the setup wizard using the Enable HTTP Server checkbox on the Configure CEE Security Settings window, so Dell platforms like PowerScale can connect to CEE.
  2. Configure or disable the AccessList - AccessList is enabled by default but not configured. You must either turn it off (if IP-based restriction is not required), or configure it with the FQDNs/IPs of the OneFS nodes that are allowed to connect to CEE.

Reinstallation with these options selected should offer relief.

Another method is to edit them in regedit and restart the Dell services. The two keys that must be adjusted are:

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\EMC\CEE\Configuration\Security\Http

"ServerEnabled" should be set to 1

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\EMC\CEE\Configuration\Security\Access

"AccessListEnabled" should be set to 0 (unless in use)

Once set, restart Dell CAVA service in services.

If the  above steps are not helping, contact Dell Support for assistance. 

Affected Products

PowerScale OneFS
Article Properties
Article Number: 000495727
Article Type: Solution
Last Modified: 06 Aug 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.