Endpoint Protection

 View Only

How to tune/optimize SEP 11.0 scans in mixed environments? 

Aug 06, 2012 07:52 AM

 

1. Scan compressed files

This can be resource consuming activity because content will be extracted, scanned and then the cache deleted. The impact on security is reduced, because archives need to be extracted to have their content used, and Auto-Protect will scan the content while extracted.

 

2. Scan tuning

"Best Application performance" is recommended to do not impact 3rd party applications. This is the default value.

 

3. Scan duration and randomization

You may reduce Scan Duration to have better control of randomization. However, keep in mind that if many hours are required to scan all system files, and if scan duration is short, you might need several days to get the scan actually completed.

Increasing Scan duration would allow you to complete scan in a faster way, but you won’t be able to define when the scan should exactly be ran (if you use randomization).

 

4. Mixed-scan environment/exclusions

You may move from Full scan to Custom scan, in order to analyze only parts of the systems, like partitions or extensions. You could also configure Active scan on a very frequent basis if the goal is to ensure main operating system data is clean.

You also need to ensure all proper applications and known files have been already excluded from scans (http://www.symantec.com/docs/TECH104326).

 

5. Multithreading

You can combine resumable scans (= Scan Duration: http://www.symantec.com/docs/TECH101386) with multithreading to improve performances:
http://www.symantec.com/docs/TECH101387

This would have significant impact on machines with multiple volumes and processors/cores.

 

6. Newer version of SEP

Last build of the product (SEP RU7 MP2) includes fixes for some scan scheduling issues (http://www.symantec.com/docs/TECH103087) but this would have an impact only if you are affected by these problems.

The new generation of SEP (12.1) brings a lot of improvement related to scan performances (i.e. file skipping, whitelisting, scan on idle - http://www.symantec.com/docs/TECH163413).

 

 

 

Best solution would be to use a mix of these settings. Based on the time it takes to complete a scan, you might tune Scan Duration/Randomization to have a good balance between scheduling and performances. You might also need to have several policies, based on system types and purposes.

 

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.