I have installed Symantec Endpoint Protection 14 on my PC having Core i5 and 4 GB RAM. After installation, it has made PC working veru slow. It takes more than 1 mintues to open browser. How can I make my PC work faster? Please provide solution for this problem.
SEP 14 Slow computers with high CPU usage
What is the ports used between SEPM 14.2 and Clients?
Hello
Appricate your help to know the ports used between SEPM 14.2 and Clients (14.2 & 12.1) to open it from firewall.
Thanks
All definition types "not available" except for AntiVirus
All definition types "not available" except for AntiVirus in client page view set to Protection Technology
This occurs after upgrade from 14.0.3929.1200 to 14.2.1031.0100
Client UI reports all definitions current and is connected to server
upgraded by install package assigned to groups clientremote.exe will also produces this condition cllient reported fine before upgrade
Exported install exe does not produce this clent reports fine after upgrade
SEP 14 MP2 Full scan hangs
Environment: Windows 7 Pro SP1 64 bit, SEP 14 MP2, UNMANAGED CLIENT
Problem description: We invoke a full scan from the client UI. The scan "hangs" after scanning about 260,000 files. By hang, we mean there is no CPU or disk activity. This is a vanilla Win 7 Pro 64 bit client - nothing special about it. The only changes that have been made are routine LiveUpdate updates. We've had no issues with this machine.
In the client UI, we briefly see on the Status page as message with a yellow background "Download Insight is not functioning correctly due to an internal logic error". The message is soon replaced with "Your computer is protected. No problems detected." on a green background. The scan is still hung at this point.
This behavior started about January 15, 2019. Is anyone aware of any content problems recently?
We've been through basic troubleshooting on this machine. We don't need advice on how to run the diagnostic tool. We are looking for a specific fix, if there is one.
SEPM14 support Linux?
SEPM14的最新版本是否支持Linux上客户端的集中管理?
如题
Translation:
Does the latest version of SEPM14 support centralized management of clients on Linux?
how to assign a policy to a particular client for some time duration
I would like to enable USB to a Particular Client for some time duration without moving it under a new group.
Clarification on EOL for SEP 12.1
Article https://support.symantec.com/en_US/article.TECH239... state SEP 12.1 will be EOL on April 3rd 2019. Specifically it says "This is the point when we stop doing bug fixes for the product."
My question is, what does Symantec consider a "Bug Fix"? Does this mean any vulnerabilities (CVEs) will be left unpatched or does it mean things like funcionality bugs will not be fixed? If it means no vulnerabilities will be patched, is this something that will be avaialble with the purchase of extended support? What does extended support provide?
I see all support expires in 2021, but it seems crazy that a security company would allow their software to "work" for 2 years with multiple vulnerabilties.
We are currently working on removing version 12 but we have a very large footprint and multiple SEPM consoles to upgrade. If we knew vulnerabilties would continue to be patched that would allow for a smoother timeline to upgrade.
Uninstall password
Hello all!
I'm trying to uninstall Symantec Endpoint Protection from an old laptop
I'm being asked to type in a password, which I don't have
I've looked online for solutions but without success..nothing works!
Apparently Windows 10 blocked or disabled or whatever (I really don’t understand much about software and computers in general) the Symantec Endpoint Protection and now I can’t get rid of it!!
Please, does anyone have any idea what I can do?
Thanks!
deployement and design guide
Hi chaps,
I need to provide some consultancy to a customer and they have the following setup.
Environment
- 220 sites in one country
- Business has grown by acquisition, so standardisation is low and complexity is high
- Multiple network configurations
- MPLS with direct connectivity to SEPM
- MPLS with VPN to SEPM network
- MPLS with no connectivity to SEPM network
- Single circuits with VPN to SEPM network
- Single circuits with no connectivity to SEPM network
- Wide range of available bandwidths across networks – ADSL to FTTP
- Approx. 1500 endpoints
- 99% Windows. A few Apple clients
- Win 7/8/10 – Mostly 10
- Multiple AD forests in place, and 800+ endpoints not in AD
- Ivanti as the primary means of endpoint management
- 7-8 different varieties of AV currently in use, at varying levels of management
- Sophos
- Webroot SecureAnywhere / Kaseya
- Windows Defender
- AVG
- McAfee
- BitDefender
- F-Prot
- ESET
SEP 14.2 setup
- Licenses purchased
- SEPM installed within Customer network
- VM on VMWare infrastructure
- Hosted
- Single instance, not HA
- SEPM Cloud not currently enrolled
- Approx. 30 clients deployed as a pilot
- Planning to deploy via Ivanti
- Only deploying to desktops & laptops – not phones or tablets
I need to deliver the following :
- Review and input into deployment strategy -
- SEPM configuration
- Client grouping and mgmt.
- Policy creation - how to build container
- Location-based logic
- Etc.
- Removal of existing AV programs - best way to remove non symantec AV from 1500 machines
- Options available, testing and package-building
- SEP Cloud – pros & cons of enabling and best practices
REST API call - PATCH /sepm/api/v1/computers
Hi all,
Goal: Move a client to a different group
There is a need to provide body to a REST API call and it is an array. So I provide this
[{"computerName":"JCK74632",
"group":
{"id": "B487A600A4B106944995683FC3321A4",
"name": "Scanned by Owner"}}]
However, I received this error:
{"errorCode":"400","appErrorCode":"","errorMessage":"Duplicate hardware keys found: [null, ]."}
Is anyone have any idea how to resolve this issue? For your information, this is an integration with ServiceNow. From what I check, this pc is in a "Default Group", do I need to delete the pc in that group only I can move to new group "Scanned by Owner"
Any idea will be helpful, Thanks in advance.
Le service Symantec Endpoint Protection s'arrête tout seul
Bonjour
J'ai plusieurs serveurs en Windows Server 2016 sur lequel sont installés Symantec Endpoint Protection 14.
Depuis une semaine, sur ces serveurs le service s'arrête tout seul. je suis obligée d'aller dans la liste des services pour les relancer.
Quand les services s'arrêtent cela me pose des problèmes dans Outlook.
Est-ce que quelqu'un est dans la même situation que moi ?
Y-a-t-il une solution ?
Merci
How to exclude a Setup.exe - SEPM
Dear,
One costumer need to exclude a file, this is a installer from a local application , the name is Setup.exe, using the checksum.exe I can export the MD5 from this file and my questions is if only I have to import my list in the Policy Components\File Fingerprint Lists for the excude or I need to do one more step ?
Regards!
Carga de Paquetes Nuevos para la version 14.2 (14 MP1)
Estimados
Necesito cargar los paqutes nuevos desde el administrado de Paquetes para la version 14.2.1023 ( 14 MP1) pero en la descarga de perfl no logro encontrar los adecuados para su implementacion
En una descarga de prueba se uso la carpeta SEP64_To_1031_SL ( en donde el contenido son unos ejecutables.)
Por favor si es factible validar procedimiento o ver desde donde poder descargar dichos paquetes de instalacion
Agradeciendo sus comentarios
Victor Ulloa
Adminstracion Infraestructura TI EmpresasOtero
Virus Definitions Out of Date
Over the past 2 weeks or so I've been getting warnings on the online management page that several of our computers (both Windows 7 and Windows 10) have out of date virus definitions. This is not the case. For one thing, the 'virus definition update request' has never once worked for me, so I have to go each computer and manually update when I get this message. Even after I do that, and run Windows udpates, and restart the computer several times, and give it plenty of time to send data, the manager still says that the definitions are out of date. So far the only solution I've found is to uninstall SEP and reinstall it. Please tell me there is another way to get this to stop happening.
E-Mail Error Dialog
I get this message when sending E-Mail for one of my two accounts, the other works fine.
Symantec Email Proxy
email send failed because the connection to your email client was interrupted
1003.8
I am using Outlook.
This started happening a few days ago, I have made no recent changes to my Protection or Outlook settings.
I can find no mention of this dialog in the endpoint help any ideas how to fix it.?
Impact of SEPM Over Deployed Status
Team,
Need urgent assistance : Running with SEP 14 version with 500+ over deployed machines, approximately for more than 60days & now it started showing
"Download Insight Malfunctioning"& Proactive Threat Malfunctioning". The issue got fixed automatically on that particualr machine next day & it keeps generating the same error on other machines randomly.
How to validate if thats causing becuase of the over deployed license? Request for solution asap? What I see is also the Antivirus definition has stopped once the machine gets that error.
Intrusion Prevention Signature Failures
We have a SEPM 14 installed on our own on-site Windows Server 2008 R2. We have 10 client computers running Win7 Pro or Win10 Pro. A few days ago I installed SEP 14.0.3752 on three Win10 Pro machines. I then read the SEPM communication file into the SEP on each machine, and it all worked well. I also saw that LiveUpdate ran on each machine to update the virus definitions. However, in SEP there is now an error on all three of these machines: Intrusion Prevention Signature Failures.
First - what does this error mean? What sort of signature are we talking about here?
And how do I fix this? I have read this post https://www.symantec.com/connect/forums/intrusion-... and have mostly tried the suggestons here, without getting any further.
Grateful for any insights.
See 2 attached images - screenshots from SEPM.
Definition update values left in PendingFileRenameOperations
Hi All,
I am seeing an odd issues on about 10% of our servers where values are being left in the "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations" key. We have tried rebooting systems multiple times but they never see to be removed and just keep piling up. Right now I have a couple servers with over 1000 lines in this key all related to Symantec. Here are some samples of what is in there:
\??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Data\BASH\19012087.kc
\??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Data\BASH\BASHIntl.000
\??\c:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Data\BASH\BASHIntl.000
\??\C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Data\BASH\BASHIntl.dat
\??\c:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Data\BASH\BASHIntl.dat
<snip>
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\reboot.sis
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\reboot.sis
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\startrollback.sis
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\startrollback.sis
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\startup.sis
\??\E:\Apps\Symantec\Symantec Endpoint Protection\12.1.7004.6500.105\Scripts\startup.sis
The above were the first few and last few of the 4983 lines in the PendingFileRenameOperations key. What makes it worse that this server is on version 14.0.3929.1200. I do have some systems that are still on 12.1.6 that are also in this state.
I have two seperate tickets open with Symantec on this issue and both times the suggestion is to upgrade, but we have done that and still having the issue.
We can uninstall, removed the key and reinstalled and the problem does go away, but it eventually shows up other places, so this is not really a viable solution.
Does anyone know why this happens? If I understood how this happens, maybe I can address the root cause.
Thanks
Martin
The problem that this is causing is that the OS is reporting that it needs a reboot because of these keys and the only way I have found to fix it is to manually remove the registry key.
Cannot install client only update
Hello,
I am having trouble installing the client only update. The installer just flashes and closes instantly, too fast to read it. You can briefly see the progress bar shoot across the screen but that is it. I tried "run as administrator" and it takes a little longer, but still closes before appearing to do anything.
System Information:
VMware Virtual Machine
Windows 10 Pro Version 1809 Build 17763.253
Symantec Endpoint Protection 14.0 RU1 MP2 build 3929 (14.0.3929.1200)
User account control is disabled.
The file I am attempting to install is: Sep_3929To1031_clientDAXMSI
I was going to try and run the Symantec Support Tool and get more information, however, I get an internal server error when I click on any links that lead to it.
Any help is appreciated.
Clients missing from report but shows on Dashboard and Monitor
Been working with support on this but so far no luck.
Running the latest version of 14, which in version number is 14.2.1031.0100.
In the home area on the dashboard, it says I have 1382 endpoints.
When I go to Monitors, select Computer Status, Time Range of Past year, it shows I have 1382 endpoints.
When I go to Reports and configure the report in this way:
Report Type: Computer Status
Select a report: Symantec Endpoint Protection Product Versions
Saved Filter: Default (and filter settings are All or *)
Time Range: Past year
I get a report that says I only have 352 endpoints. The problem is getting worse as I'm upgrading my clients to 14.2.1031.0100 from 14.0.3897.1101 or from 14.2.770.0000.
Symantec support seems to be stuck on a duplicate hardware ID issue, but even their tool only shows about 10 duplicate hardware IDs. I've also tried to put in place the duplicate hardwareID logic in the configuration file, but that doesnt seem to do anything.
Anyone have any ideas?