Endpoint Protection

 View Only

Installation and Configuration of Shared Insight Cache 

Jan 15, 2012 01:28 AM

The Symantec Endpoint Protection Shared Insight Cache eliminates the need to scan files in a virtualized environment that Symantec Endpoint Protection has determined are clean. When Symantec Endpoint Protection scans a file for threats and determines it is clean, the client submits information about the file to Shared Insight Cache. When another client subsequently attempts to scan the same file, the client can query Shared Insight Cache to determine if the file is clean. If the file is clean, the client can bypass virus scanning on that particular file. If the file is not clean, the client scans the file for viruses and submits those results to Shared Insight Cache.

 

Note:

Shared Insight Cache is only available for the clients that perform scheduled scans and manual scans.

Shared Insight Cache runs independently of Symantec Endpoint Protection. However, you must configure Symantec Endpoint Protection Manager to specify the location of Shared Insight Cache so that your clients can communicate with Shared Insight Cache. No special license is required to install or run Shared Insight Cache.

 

Install Shared Insight Cache

Pre - Requisite

  1. Install .net Framework 4.0.
  2. Windows 2003/2008.

Installation

  1. Double-click on the following file to launch the installation program (the msi can be found under Symantec_Endpoint_Protection_12.1_RU1_Part2_Tools_and_Documents_EN\Tools\SharedInsightCache):

msiexec /i SharedInsightCacheInstallation.msi

 

2. In the Shared Insight Cache Setup wizard pane, click Next. Read through the Symantec Software license agreement, check I accept the terms of the License Agreement, and then click Next.

 

 

3. On the Destination Folder pane, do one of the following tasks:

 

 

To accept the Click default location for  Shared Insight Cache

Click Next.

To specify a different location for Shared Insight Cache

 

Click Change, browse to and select the destination folder location, and click OK.

 

Then on the Destination Folder pane, click Next.

 

                                                               

 

 

4. On the Shared Insight Cache Settings pane, specify the following Shared

Insight Cache settings:

 

 

 

Cache Usage (% of Physical Memory)

 

Specify the maximum size of the cache.

When the cache exceeds this threshold, Shared Insight Cache prunes the cache size.

Listening Port

The port on which the server listens.

Status Listening Port

The port the server uses to communicate status within the system.

 

5. Click Install to begin installing Shared Insight Cache.

 

 

 

6. Click Finish.

 

7. Once complete, configure the policy for client to communicate Shared Insight Cache server . Open the SEPM console-> click on Policies tab- >Select the Antivirus –> Antispyware policy -> click on Global Scan Options under Advanced Options and enter the details of the SIC server. Click OK and assign the policy to the groups.

 

 This configuration will be taken by clients and will use SIC feature for scans.

Statistics
0 Favorited
9 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Aug 29, 2016 01:09 AM

Shared Insight Cache use improves performance in virtual infrastructures. Files that Symantec Endpoint Protection clients have determined to be clean are added to the cache. The subsequent scans that use the same virus definitions version can ignore the files that are in the Shared Insight Cache. Shared Insight Cache is used only for scheduled and manual scans.

https://support.symantec.com/en_US/article.HOWTO81020.html

 

Aug 28, 2016 01:11 AM

What is the performance defference between normal SEP client and with Shared Insight Cached SEP client?

does it imporve Auto Protect as well ?

 

Thanks

 

Oct 18, 2013 02:44 AM

How many clients can be supported by 1 SIC server - we have 23000+ clients spread out - can I use 1 SIC server or do I need a dedicated SIC server for each of the sites I have GUP's?

I want to implement this but then again the customer wants to know whether a GUP can be a SIC server as well..

Oct 10, 2013 04:45 AM

How many clients can be supported by 1 SIC server - we have 23000+ clients spread out - can I use 1 SIC server or do I need a dedicated SIC server for each of the sites I have GUP's?

Oct 08, 2013 06:09 AM

Thanks for the article.

I still have a question, is it possible to use a Windows 2012 server for the SIC function?

Is it supported?

Jul 10, 2013 05:49 AM

Network-based Shared Insight Cache configuration options

Option

Description

Require SSL

Check to indicate that Shared Insight Cache uses SSL authentication.

If you use SSL authentication, you must specify the authentication user name and password.

Hostname

Specify the host name for Shared Insight Cache.

Port

Specify the port that Shared Insight Cache uses.

Username

If you changed the SharedInsightCacheService.exe.config file to set Shared Insight Cache to use Basic authentication with SSL or Basic Authentication with no SSL, type the authentication user name.

Change Password

If you changed the SharedInsightCacheService.exe.config file to set Shared Insight Cache to use Basic authentication with SSL or Basic Authentication with no SSL, use this option to specify and confirm the authentication password.

 

Jul 10, 2013 05:23 AM

great thanks for sharing.  but i have one question about "username":

- For my understanding, username is login account of SIC server. So that what user permission for this account?  Can I create one basic user for this "username"?

 

Thanks.

 

May 23, 2013 03:36 AM

HI Pete, 

Thanks for the sharing.

 

Jun 06, 2012 10:03 AM

Thanks a lot for that usefull article.

Jan 18, 2012 01:10 AM

How much system recource SIC server with used?

It's the memory that would have been configured like Cache Usage (% of Physical Memory). (refer the screen capture posted above)

What If our SIC server is offline then still SEP client bypass clean files?

if SIC server is offline, all files will be scanned as there is no reference to check.

Can we use shared insight cache for physical systems too?

Yes, you can use it for physical systems.

How SEP clients contact SIC and how much nework utilized to check every know and unknow files?

when you edit AV/AS policy you configure the clients to contact SIC server (refer the screen capture posted above)

Does we configure SIC centrally for remote location clients as well?

It would be recommended to have it set it locally.

Jan 17, 2012 11:54 PM

Pete.

 

Nice Article. But I have some query here:

 

How much system recource SIC server with used?

What If our SIC server is offline then still SEP client bypass clean files?

Can we use shared insight cache for physical systems too?

How SEP clients contact SIC and how much nework utilized to check every know and unknow files?

Does we configure SIC centrally for remote location clients as well?

 

 

 

Related Entries and Links

No Related Resource entered.