Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

Install Client Feature Set vs Client Policies

$
0
0
I need a solution

Let's say I create 2 groups: One is named "Server-Full-Protection" and the other is named "Server-Basic Protection"

My next step is installing a "Full Protection" client on one server and putting it in the "Server-Full Protection" group.  Then, I install a "Basic Protection" client on another server and put it in the "Server-Basic Protection" group.

My first question is:  Will the policy settings in those groups change to reflect what is installed on the servers via the client? (i.e. - which protection technologies are checked in the policies)

My second question: If I decide to switch these servers to opposite groups, will those protection technologies automatically enable/disable?

Thank you for your help.

0

Can SEPM12 repair duplicate IDs automatically?

$
0
0
I need a solution

Symantec updated the KB https://support.symantec.com/en_US/article.TECH163349.html recently that states that version 14 MP1 repairs SEP IDs automatically.

I am not sure if we can apply the solution for SEPM 12.1 RU6 MP9, so that SEP12 clients automatically re-generates their ID before re-attempting registration with the SEPM.

Solution:

1. Stop the SEPM service.
2. Go to this location:
"C:\Program Files\Symantec\Symantec Endpoint Protection Manager\tomcat\etc"
3. Edit the file "conf.properties".
4. Add these lines to the file:
scm.duplicatedhwkey.fix.enabled=true
scm.duplicatedhwkey.fix.client.csnreset.count=3
scm.duplicatedhwkey.fix.client.csnreset.time.range=86400000
5. Close and save the conf.properties file
6. Start the SEPM service.

0

Schedule virus definition update for some clients

$
0
0
I need a solution

Hello,

Is there a way to schedule the virus devinition update at a precise time for some clients ?

For exemple, I need to update a server only between 2 and 2:30 AM. How can I achieve that ?

Thanks for any help !

0

SEPM not shows Win10 SEP clients

$
0
0
I need a solution

Hi,
we have a Windows Server 2008 R2 with Symantec Endpoint Protection Manager 12.1.7369.6900 MP9. The SEPM
is istalled on our server, not in the cloud. This server also has the Symantec Endpoint Protection
client, version 12.1.7369.6900 and 12.1.6318.6100

We have 173 workstations. The workstations are Windows 7.
They all have the Symantec Endpoint Protection client, version 12.1.6318.6100.

We add two workstations with new Windows 10 Pro machines version 1709.
After installing the client version 12.1.7369.6900, it does not appear in the list in the SEPM.

SEP installs just fine, and is able to communicate with SEPM and successfully update it's content no problem.

But in the tab Detail in the list it is indicated that there are two clients.

We have only one domain in SEPM. SEP was installed as part of a package deployment from SEPM.

There are ideas why clients are not displayed? Thanks in advance!

0

Schedule virus definition update

$
0
0
I need a solution

Hello,

I use SEPM 14. Is there a way to schedule the virus definition update for some client at precise time ? 

For example, I need to update a server only between 2 and 2:25 AM during the night. Is that possible ?

Thanks for your help !

0

Error on Memory axploit Mtigation

$
0
0
I need a solution

Memory exploit Mtigation is not functioning correctly yuor protection definition may be damaged or your product installation may be corrupt

0

Reports different from different SEPMs

$
0
0
I need a solution

We have a primary SEPM and primary SQL database, as well as a disaster recovery SEPM and disaster recovery database.  The databases are setup up for a 2 way replication.

We are using Computer Status reports for the purposes of auditing, and the report from the primary server contains some different information than the report from the disaster recovery server.  Why is that?  How do we get the reports to look the same?  We need a single, accurate report for auditing purposes.

0

Microsoft Recommended Exceptions for anti-virus

$
0
0
I need a solution

I'm currently reading up on recommended anti-virus exceptions for Exchange Servers.  It turns out, there are a SLEW of them:

https://technet.microsoft.com/en-us/library/bb332342(v=exchg.150).aspx#Directory

Is SEP14 smart enough to exclude these as-is, or will I need to go through and enter each one of these exclusions into my policies?

Thank you.

0

Update Sylink file using Host Integrity Check

$
0
0
I do not need a solution (just sharing information)

Update Sylink file using Host Integrity Check on SEPM 14

Hello,

Recently , I had to update client communication file (sylink.xml) for the pupose of merging two sites. Firslty I used "sylinkreplacer" for the activty. It helped me move alomost 60% of clients to the new server. However, it was failing on the rest of the system due to access, communication and other issues. I was stuck up with almost 1.5k systems.

I wanted have an option which can update the Sylink fine using the priviladge of SEP(already in place) on the clients. I found that the Host Integrity Check( HIC) has the abilty to run scripts on the endpoint with in SEP. 

I have used a custom HIC policy, which will donwload the Sylink.XML, SylinkDrop.exe and a BAT file a from IIS or FTP server and execute the batch file for updating the Sylink.XML file.  

Attached the Sample policy, Screenshots and the othe sample files. 

Thanks.

0

How to make sure that SEPM Clients state is delete for no logon/Office longer than 7 days?

$
0
0
I need a solution

i should make SEPM Clients state is delete for no logon/Office longer than 7 days.

which settings suitable for my states? A or B ?

A : Client log settings Expires after "7"days

B : Delete logs olders than "7" days???

0

Upgrading from 12.1.6 to 14.0.1 error

$
0
0
I need a solution

I have error during database upgrade. Log shows:

"java.sql.SQLException: [Sybase][JDBC Driver][SQL Anywhere]Value 4294967040 out of range for destination"

I have found same error and solution here"

http://www.symantec.com/docs/TECH248192

but 3 point of solution "3. Copy the attached ShrinkEmbeddedDB.bat to the SEPMs Tools folder"

maybe stupid question but how to download ShrinkEmbeddedDB.bat ??

0

Scan Exception for SEP14

$
0
0
I need a solution

Hello.  I'm in a new role, and it's my primary duty to transition my company from a Trend Micro AV product to SEP14.  The current scan exceptions are currently set for our Trend Micro clients.  Are these considered best practice for SEP14 as well?

Desktops and Laptops


C:\Program Files (x86)\Citrix, Google, Microsoft Office, Microsoft SQL Server, Mozilla Firefox, ScanSoft, Neevia.com
C:\pagefile.sys 
C:\windows\system32\spoolsv.exe
d:\pagefile.sys 

Citrix Servers


C:\Program Files (x86)\CA, Citrix, Google, MIP, Microsoft Office, Microsoft SQL Server, Mozilla Firefox, Neevia.com
C:\Program Files\Citrix, Citrix\1, Common Files\Citrix, Citrix\Independent Management Architecture
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Temportary ASP.NET Files\citrix_pnagent, SoftwareDistribution\DataStore
C:\Windows\system32\WBEM\Logs, System32\IIS
D:\ 
D:\pagefile.sys 
C:\Windows\System32\drivers\CVhdBusP6.sys, drivers\CVhdMp.sys, drivers\CfsDep2.sys, drivers\bnistack6.sys
C:\Windows\System32\csrss.exe, smss.exe, spoolsv.exe, userinit.exe, winlogon.exe, 
D:\pagefile.sys 

Standard Servers


C:\Program Files (x86)\CA, Citrix, Google, MIP, Microsoft Office, Microsoft SQL Server, Mozilla Firefox, Neevia.com
D:\MIP Share 
D:\Program Files (x86)\Microsoft SQL Server
D:\Program Files\Microsoft SQL Server
c:\pagefile.sys 
d:\pagefile.sys 
0

High CPU Load - Manager Webservice

$
0
0
I need a solution

Hello,

i've a problem with Symantec Endpoint Protection Manager.

As Soon as I start the Webservice I recognize a´n heave increase of the CPU Load on the Server. This Error comes from Windows Server reporting. I can cansel the jobs, but they reapear. I need to Stop the SEP Manager - Web Service to stop the errors.

I did an manuel update of the Installation (running AUPDATE.EXE) But this does not get any effects onbn the generell Performance after starting the Webservice again. 

In the Windows Eventlog I get the following error:

Name der fehlerhaften Anwendung: httpd.exe, Version: 2.4.16.288, Zeitstempel: 0x58245da6
Name des fehlerhaften Moduls: secars.dll_unloaded, Version: 14.0.2332.100, Zeitstempel: 0x589d9dcd
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00034570
ID des fehlerhaften Prozesses: 0x784
Startzeit der fehlerhaften Anwendung: 0x01d3951e6d7189a1
Pfad der fehlerhaften Anwendung: D:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\apache\bin\httpd.exe
Pfad des fehlerhaften Moduls: secars.dll
Berichtskennung: b259cfa9-0111-11e8-80d3-00155d736303
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: 

How can I fix this error? Can I update the Apache alone to fix this error?

Thanks an kind regards

Thomas

0

14.0.1 Hot Fix 2 Still Crashing on Remote Connection

$
0
0
I need a solution

After applying hotfix 1 for the "Product Error Requires Attention" on some of my machines, I noticed using Bomgar to remote into clients would cause the crash as described here:

https://support.symantec.com/en_US/article.TECH248...

I applied the new hotfix today and SEP still crashes when remoting into the machine, but this time without a popup. The GUI will crash and all the services will then stop and then restart.

I have a case in, but the engineer is telling me the only way to roll back is to uninstall (using cleanwipe) from all the machines I've updated and then re-install fresh. (Case 13986722). Are there any other answers for me?

0

SEPFL: Does SEP even scan the whole file? (Data presented)

$
0
0
I need a solution

I have collected data which suggest that SEP takes the same time to scan files, regardless of their size.  How can this be?

I have been working to time the antivirus software.  I have a script that generates human-readable files by randomly selecting words from the system dictionary (/usr/share/dict/words).  Each line in the file is ten words long.  I then time how long it takes to run cat on each file, directing stdout to /dev/null.  For the experiment in this post, I am generating 500 files, and varying the length to see how it affects the run time, first with the SEP cache disabled, and ensuring that the files are not in the system cache (echo 3 > /proc/sys/vm/drop_caches).  Then, it is tested with only the SEP cache disabled.  Finally, the SEP cache is enabled, the test is run a few times to ensure that the files are cached, and then timings are taken.

As I understand it, if a file is in the SEP cache, SEP will not scan it.  Therefore, the time to read the files when they aren't in cache minus the time to read the files when they are should equal the time it takes to scan the files.  In the attached PNG, it can be seen that the graphs of the times with and without SEP cache are basically parallel, thus the difference between the two is constant.  This implies that SEP requires a constant time to scan files, regardless of how big they are.  This seems absurd.

How can this be possible unless SEP is not scanning the entire file?

For those who want a rough estimate of disk space, remove a 0 from the number of lines; that's about how many kB each file is.

These tests were also run on binary files and returned the same results.

0

Pass username and Password to Endpoint Console Login

$
0
0
I need a solution

Hi,

I wanted to know if it's possible to send the username and password directly via URL parameters to the SEP Console for an automatic login? 
Example: https://serverav1:8443/console/apps/sepm?username=admin&password=password

Thanks in advance for any hints.
Best Regards,
Michael

0

Microsoft 2007 Excel getting stopped soon after enabling macros

$
0
0
I need a solution

Hi,

We have recently upgraded our SEPM from 12.x to 14.0.3876.  After upgrading client package, Users with MS Office 2007 version installed in their computer are facing issue while enabling macros. Soon after enabling macros, Excel gets crashed and doesn't open. We have tried unckecking memory exploit mitigation in few clients for which it works for some computers but not for all. Unchecking the same in sepm console shows error for all sep clients. Please help.

Regards,

Anishk

0

Host Integrity Check Logs are not uploading to SEPM

$
0
0
I need a solution

Hello,

I have created a Host Inegrity Check (HIC) Policy to check presence of some registry keys.  

The HIC policy run successfully and create logs on the client end.  However it doesn't upload to the SEPM. 

All other security logs are getting uploaded to the SEPM, only HIC check logs are not going through.

I'm chceking the logs under Monitor-> Logs -> Compliance -> Client Host Integrity

Any thoughts on this issue?

Thanks.

0

SQL query to get list of computers requested full zip

$
0
0
I do not need a solution (just sharing information)

select SEM_COMPUTER.COMPUTER_NAME,CONTENT_EVENTS.*

from CONTENT_EVENTS

INNER JOIN SEM_AGENT ON CONTENT_EVENTS.AGENT_ID = SEM_AGENT.AGENT_ID

INNER JOIN SEM_COMPUTER ON SEM_AGENT.COMPUTER_ID = SEM_COMPUTER.COMPUTER_ID

where CONTENT_CATEGORY = 'AV_DEFS'AND CONTENT_NAME Like '%Definitions%'

0

Configure LiveUpdate policy to use GUPS and LiveUpate server

$
0
0
I need a solution

Hello,

I have a situation where our SEPM (Version 14 MP2) is located in the USA and we have a remote office in Tokyo. We have a GUP configured on the remote site that is working fine. However I have been informed that a few users do not actually go into the remote office very often so the clients are not being updated.

Is there a way to configure the LiveUpdate Policy to first use the GUP and if it is not available to then contact a default Symantec LiveUpate server? It appears in the GUP setting that it can connect to a default management server if the GUP cannot be contacted. But I dont see where I can configure it to connect to a Symantec LiveUpdate server within the GUP settings.

If I check use a default Symantec LiveUpdate server on the main Server Settings page will it use the GUP and then look to Symantec server?

Thanks for the help,

STL

0
Viewing all 10484 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>