> Source: [sk183635](https://support.checkpoint.com/results/sk/sk183635)

# sk183635 - Threat Hunting  status "Unavailable"  with Error description "Data Upload fail"

| Property | Value |
|----------|-------|
| Solution ID | sk183635 |
| Date Created | 2025-07-08 |
| Last Modified | 2025-09-20 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |

## Symptoms

- * Some Endpoint clients fail to send Threat Hunting Information.
* In the Infinity Portal \> Asset management, machines show "Threat Hunting Status" as Not Available" and the "error description states "Data Uploading Failed".
* The machine name cannot be found when searching in the Threat Hunting tab.
* The NGAV.log file indicates an HTTP error or an SSL/TLS error.  

  **[dd8:9] [Error] source: (NGAV.EDR.Http.Cloud.CloudHandShake) message: ( Http error --> (HttpRequestException) --> An error occurred while sending the request. | Inner Exception: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. | going to nap for: 1 min ) 
  <br />
  .............
  [dd8:5c] [Trace] source: (NGAV.EDR.Http.Cloud.CloudHandShake) message: ( RPC failed: System.Net.Http.HttpRequestException: An error occurred while sending the request. ---> System.Net.WebException: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid according to the validation procedure.
  <br />
  ............
  Errors found: [(NGAV.EDR.Http.Cloud.CloudHandShake): Http error --> (HttpRequestException) --> An error occurred while sending the request. | Inner Exception: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.**

## Cause

TH traffic is being intercepted and blocked by the firewall.
**The Threat Hunting (TH) flow consists of the following 5 stages:**   

1. Authentication with Cloud Infra using TH access key and client ID.
2. Retrieve contract information from the Threat Hunting system.
3. Authentication with Cloud Infrastructure using the DataTube access key and client ID.
4. Obtain signed URL for data transmission.
5. Send data to DataTube using the signed URL.

The error **Data Uploading Failed** indicates a problem with stage 5, where the data fails to be sent to DT.  

In most cases, the **NGAV.log** file contains HTTP errors associated with different stages of data transmission. These errors typically suggest that while the endpoint successfully initiated the information send request, the data failed to reach its destination.  
The root cause of the failure is often due to specific Threat Hunting traffic being blocked by the Security Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
