Endpoint Protection

 View Only
Expand all | Collapse all

Client shows def updated but Manager shows client with old def

Migration User

Migration UserDec 11, 2013 10:09 AM

ℬrίαη

ℬrίαηDec 11, 2013 10:23 AM

  • 1.  Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 08:13 AM

    Hello guys..

    SEPM is showing about 700 clients out-of-date...

    I checked one client side, and it is updated, 10/dec/2013 - R17. The Manager Home GUI has the same, so OK.

    But, when I search for that client in the Manager, it is out of date..

    I saw the log client side, and it got definitions from the Manager correctly.

    Client is connected to Manager perfectly...

    Client is 12.1.2 - Server 2008

    Manager is 12.1.3 - Server 2008

    Using SQL Server

    Why Manager does not update the datas from clients?

     



  • 2.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 08:16 AM

    is there multiple instances of the client or just one?



  • 3.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 08:16 AM

    Are you using Clone image ?

    If yes please check this

    How to repair duplicate IDs on cloned Symantec Endpoint Protection 12.1 clients

     

    Article:TECH163349 | Created: 2011-06-27 | Updated: 2013-05-17 | Article URL http://www.symantec.com/docs/TECH163349

     



  • 4.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 08:18 AM

    the client is in push mode or pull mode? may be it needs some time to upload logs to sepm.



  • 5.  RE: Client shows def updated but Manager shows client with old def



  • 6.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 09:58 AM

    Guys,

    James:

     - No clone;

    Brian:

     - No, just one;

    Rafeeq:

     - Pull mode. Last time status changed is current. In the manager, it shows the definition 07/dec/2013 r8

    Aj:

     - I will check...

     

     



  • 7.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 10:01 AM

    Is this only happening on this one client? Or others as well?



  • 8.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 10:09 AM

    About 700



  • 9.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 10:11 AM

    If clients are truly updated but are not reporting correct status, it would appear to be more of a cosmetic issue. Have you tried updating one client to 12.1.3 so it is on the same version as the SEPM?



  • 10.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 10:19 AM

    Well... I have a client 12.1.2 with problem... 64 bits, server 2008

    My notebook is 12.1.2, without problem, 64 bits, windows 7...

     

    If it was a problem with version, it should happened before, because I am running 12.1.3 more than 1 month..

    I changed the GUP police, adding four more clients... This is the only current change I did.

    I though anything about SQL server, but, all clients should be wrong, right?

    I think I need to open a ticket.... :(



  • 11.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 10:23 AM

    ...unless it's specific to 2008.



  • 12.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 11:27 AM

    Hello,

    SEPM console is just showing what is in the DB and the DB is populated with what comes from clients...

    Please, have a look at the <SEPM installation folder>\data\inbox\agentinfo and let us know what you see:

    - few files or several files?

    - .tmp or .dat files?

    - the amount of files is increasing, fixed or just up and down with trend to zero?

    The expected behavior is the following:

    - SEPM webserver moves log files received from clients to the inbox subfolders

    - those files are .tmp during the transfer and changed to .dat when they are complete

    - .dat files are parsed and entered into the DB, hence deleted

    That's you should see new .tmp entering in the folder, renamed as .dat and then deleted automatically, different behaviour could be a sign of something wrong in processing clients' logs.

     



  • 13.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 12:28 PM

    Beppe,

    I have 69 items... and it gone to 70 and 69 again..

    I have a lot of like this:

    2b788460-72ad-4c35-8e5d-d162ab3cf898.dat.err

    and like this:

    52b38cd2-e25d-4485-b903-56f5cbff1c37.tmp

    .dat.err and .tmp

    And now?



  • 14.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 01:47 PM

    Well..

    I stopped SEPM services...

    I backuped the files inside the folder...

    Deleted all files...

    I did it in both SEPM servers, I have 2.

    I started the services... and now... I think it is working great!.. I just have 1 file now, at least.

    But, why it occurred?

     

    Rafeeq, I saw a post that you helped a guy, take a look:

    https://www-secure.symantec.com/connect/forums/sepm-reports-virus-defs-outdated-client-shows-date-defs-console



  • 15.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 01:47 PM

    Hello

    Hope all communication is good from client and Server?

    If not please check and update.

    Regards

    Ajin

     



  • 16.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 11, 2013 01:54 PM

    Those are just tmp files and can be safely deleted. Perhaps something got hung up.



  • 17.  RE: Client shows def updated but Manager shows client with old def
    Best Answer

    Posted Dec 12, 2013 05:41 AM

    Guys, I did those steps below, like rafeeq shown in another post:

     

    1. Browse to \Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\agentinfo

    2. Look for any .err files or tmp files & Dat files

    3. If you find anything which is not processed by sepm then it might be the reason for the client data loss

    4. Stop SEPM services from services.msc 

    5. Delete all the files inside the location \Program Files\Symantec\Symantec Endpoint Protection Manager\data\inbox\agentinfo

    6. Restart the SEPM services.



  • 18.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 12, 2013 05:47 AM

    Wow!! :)

    it was from here may be handy next time 

    Symantec Endpoint Protection Manager does not parse client forwarded logs in a timely manner.

     

     
     

    http://www.symantec.com/business/support/index?page=content&id=TECH91835



  • 19.  RE: Client shows def updated but Manager shows client with old def

    Posted Dec 12, 2013 07:19 AM

    Hello,

    sorry for the late response, .err files are indication that there was an issue in parsing them, the fact their amount is not increasing it means it got stable. It happens the parser gets stuck in trying to process damaged files, hence, you resolved the issue by cleaning those files up.