How to troubleshoot queued security actions

When you trigger a security action from your Prey panel, the instruction must reach the Prey client installed on the device. If the communication is interrupted, the action will not execute and will remain stuck in a "queued" or pending state.

How to identify a communication issue

Before troubleshooting, confirm that the issue is actually a communication block:

  • Pending status: A yellow alert or yellow bar appears next to the action name in your Prey panel.
  • Activity log gaps: Go to the device's activity log. You should see [security action name] requested. If the device receives the instruction, it logs [security action name] started, followed by [finished successfully]. If the "started" or "finished" logs are missing, a block is preventing the action from executing.
  • Device check: If you have physical or remote access to the endpoint, you will notice the action is not running (e.g., the screen lock or alert message does not appear on the screen).

Diagnostic workflow

To restore communication and execute your queued actions, follow these troubleshooting steps in order.

Step 1: Verify network and connectivity

Before diving into system settings, verify that the endpoint can actively reach the internet and our servers.

  • Open a web browser on the target device and load a new webpage to confirm active internet access.
  • Disable VPNs: VPNs can route traffic in ways that interfere with Prey's background communication. Temporarily disable any active VPNs on the device and check if the queued action starts.
  • Firewall and proxy configurations: Strict corporate networks may block the Prey client. Ensure the necessary allowlist rules are applied to your network firewall or endpoint protection software. Please refer to our guide on how to whitelist Prey in your security solution.
Step 2: Check OS permissions and restrictions

Modern operating systems restrict background processes to save battery or system resources. Ensure the OS isn't silently blocking Prey.

  • Admin privileges: Ensure the Prey client was installed with administrator/root privileges; otherwise, critical actions (like Lock or Wipe) will lack the necessary permissions to execute.

For more details, check our guide on Configuring OS permissions for the Prey desktop agent

Step 3: Restart the local service

If the network is clear and permissions are correct, the local Prey background service might be frozen. You can kill the process to force it to restart. Wait a few minutes after executing the command for the client to restart automatically, then check if your queued actions execute.

  • Open the Command Prompt as Administrator and execute:

    taskkill /F /IM node.exe
  • Open Terminal, execute the following command, and enter your administrator password:

    sudo pkill -f prx
  • Open Terminal, execute the following command, and enter your administrator password:

    sudo -u prey /usr/lib/prey/current/bin/prey -D
Step 4: Reinstall the Prey client

If restarting the service doesn't work, the local installation data may be corrupted. Use our repair tools to force a reinstallation without losing the device's connection to your account. Refer to our guides on how to uninstall Prey for computers and how to install and add devices to Prey

Step 5: Contact support with client logs

If you still need help please open a ticket including your Device Key (found in your browser's address bar when viewing the specific device in your Prey panel) and the prey.log and prey.conf files.

How to extract logs from the affected device:

  • Navigate to C:\Windows\Prey. Copy both the prey.log and prey.conf files.

  • Open Terminal and execute the following commands to read the logs. Copy the output and paste it into a text document to attach to your ticket:

    cat /var/log/prey.log
    cat /etc/prey/prey.conf

Please reach out to us with this information from the Help widget on your Prey panel.

Was this article helpful?

0 out of 0 found this helpful