Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Clients Not Updating definition from SEMP MR2

Updated: 21 May 2010 | 27 comments
lsdlsd's picture
0 0 Votes
Login to vote

My SEPM server not getting any update from Liveupdate. It tells that :

-------------------------------------

June 4, 2008 9:45:17 AM CEST:  LiveUpdate succeeded.   [Site: ServiceAVIT]  [Server: ServiceAVIT]

June 4, 2008 9:45:17 AM CEST:  LUALL.EXE finished running.  [Site: ServiceAVIT]  [Server: ServiceAVIT]

June 4, 2008 9:45:17 AM CEST:  LUALL.EXE finished.  There were no new
content updates. Return code = 1.  [Site: ServiceAVIT]  [Server:
ServiceAVIT]

June 4, 2008 9:44:05 AM CEST:  LUALL.EXE has been launched.  [Site: ServiceAVIT]  [Server: ServiceAVIT]

June 4, 2008 9:44:05 AM CEST:  Download started.  [Site: ServiceAVIT]  [Server: ServiceAVIT]
-------------------------------------

After i run Liveupdate from SEPM>Admin>Servers>Local Site>Download Liveupdate Content and get the message above, in the Show Liveupdates Downloads it tells that "No liveupdate content has been downloaded". Something else is that in the Home Page of SEPM, in the VIRUS DEFINITION DISTRIBUTION  the latest symantec verision refers to the latest definition release that my unmanaged SEP downloaded.

This issue is really getting me angry cause if i update manually the server with the .jdb definition files clients updates their content but when i run live update from the SEPM it allways says thet "There were no new
content updates".

How can i fix this problem. I'm relly spending hours & days on this issue. And i've tried SEPM MR0 didnt work. SEPM MR2 still didnt work. Also tried it with embedeed database and SQL database.


Please help me, to find where the problem is commig form and what should i do to fix this.

Thank you!

Comments

CommerceSNI's picture
04
Jun
2008
0 Votes 0
Login to vote

What do you have set under Admin->Servers->local site->edit site properties->live update tab?
The things you want to download need to be checked off under content types, languages and make sure you have a source server set also.
 
While you are in there you might want to save fewer versions of the downloaded content as it takes a fair amount of disk space, most ppl seem to be happy with 3-5 revisions.
 
If that is all set properly, maybe your firewall is preventing the download? How about other networking issue, can you resolve DNS to the symantec liveupdate download site?
 
I can not see your images that you posted.
lsdlsd's picture
05
Jun
2008
0 Votes 0
Login to vote

Thank you for your reply!

While searching to find why the problem is comming for in the log file "SesmLu.log" i'm finding some rrows tellnig that:
Jun 02 08, 07:20:26 PM ERROR sesmAvClient64en ProductUtil: Unable to read xml file: "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\content\LuConfig.xml". at .\ProductUtil.cpp[322]

Jun 02 08, 07:20:26 PM ERROR sesmAvClient64en LuConfig: Unabled to open LuConfig.xml. Default to allowing content at .\LuConfig.cpp[72]

Jun 02 08, 07:20:26 PM ERROR sesmAvClient64en ProductUtil: Unable to read xml file: "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\content\LuDownloadedContentArray.xml". at .\ProductUtil.cpp[322]

Jun 02 08, 07:20:26 PM INFO(Med) sesmAvClient64en DownloadedContentArray: Unabled to open LuDownloadedContentArray.xml.

Jun 02 08, 07:20:26 PM INFO(Med) sesmAvClient64en SesmLu: WelcomeText callback...

Jun 02 08, 07:20:26 PM INFO(Med) sesmAvClient64en SesmLu: WelcomeText callback... finished. Result: 0

Jun 02 08, 07:20:26 PM INFO(Med)  SesmContentCatalog: Entered Init().

----------------------------------------
On how i understand this error it seems that the update process is searching for a file named LuConfig.xml and osome other file with the extension .xml hosted in the "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\content\"


Also i've upgraded my clients to the MR2 version and the proactive threat protection is turned off and waiting for updates. But even the rapid release of the xxxx.jdb file is not updating my server any more.
Also if theres any problem with the database I have 5 days trying to download the ludbfix.zip but the Ftp ling isn't working.

I don't know what else to do with this program. Every moment giving a new problem or and when trying to fix one comes out another.


Please Help me.

Regars
LSDLSD


DDPatil's picture
12
Jun
2008
0 Votes 0
Login to vote

I am also facing same Issue here. MR2 is not updating my client's virus defination.
 
I think liveupdate of console is working problem. below is detail for liveupdate message in Manager console
 
June 12, 2008 2:50:33 PM GMT+05:30:  LiveUpdate succeeded.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:50:33 PM GMT+05:30:  LUALL.EXE finished running.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:50:33 PM GMT+05:30:  LiveUpdate will start next on Thursday, June 12, 2008 6:50:33 PM GMT+05:30 on sv-sug-0002.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:50:33 PM GMT+05:30:  LUALL.EXE successfully updated the content. Return code = 0.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:56 PM GMT+05:30:  Symantec Network Access Control Win64 11.0 (English) is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:55 PM GMT+05:30:  Symantec Network Access Control Win32 11.0 (English) is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:54 PM GMT+05:30:  Symantec Endpoint Protection Win64 11.0 (English) is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:54 PM GMT+05:30:  SESM AntiVirus Client Win64 is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:53 PM GMT+05:30:  Symantec Endpoint Protection Win32 11.0 (English) is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 12, 2008 2:49:53 PM GMT+05:30:  SESM AntiVirus Client Win32 is up-to-date.    [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
 
& In Home page under "Virus Definitions Distribution" It is showing as below
 

Display:

 

 

Definitions

Computers

 

                   

2008-06-03 rev. 037

37%

 

2008-06-01 rev. 021

1

                 



Latest Symantec Version:

2008-06-11 rev. 050

Latest Manager Version:

2008-06-11 rev. 050

This all about Manager console & Client is showing 2008-06-03 rev. 037

 

 

 
 
Piyush Jhunjhunwala's picture
12
Jun
2008
0 Votes 0
Login to vote

You might want to re-register Symantec Endpoint Protection Manager with LiveUpdate:

Open a DOS command prompt.

Go to C:\Program Files\Symantec\Symantec Endpoint Protection Manager\bin

Type lucatalog.exe -update

Piyush Jhunjhunwala

| Technical Support Analyst | Enterprise Support ( Endpoint Security) |
| Symantec Corporation | www.symantec.com |

DDPatil's picture
13
Jun
2008
0 Votes 0
Login to vote

Hi Piyush,
 
Thanks for your attention (reply). I tried below mention command, But no client has been updated his virus def.
 
How can I stress this. Because every client is showing green spot. and I have not find any event for liveupdate at server side as well as client side.
 
Before Migration very client is getting virus defanition regulary.
Client are not updating Virus defination since, I did the Mirgration from 11.0 to MR2 and All client upgrade to 11.0.2000.1567 version.
 
Additional I have removed folder which contains 35gb data named "{1CD85198-26C6-4bac-8C72-5D34B025DE35}"  and "{C60DC234-65F9-4674-94AE-62158EFCA433}"
 
But during live update its again created above mention folder with 327MB and 325MB data respectively.
 
please let me know how to stress this issue.
 
Thanks and Regards,
Dattatray Patil
 
 
 
 
 
 
susanthas-123's picture
14
Jun
2008
0 Votes 0
Login to vote

Hi DDPatil,

The folders you've deleted are important. The one ending with 33 contains the 32bit virus def for the client PC's. So even if you delete them they will recreate but it's not recomneded. If you want to delete then delet the contents inside those folders.
Apart from that the Live update successfull but no conents seems to be a big issue for me. First thing I found is the envirometn I'm working having proxy server and we assume it can be due to proxy caching SEPM will never get the updates but only the contents reterived from teh cahce and tha is no good. Even I face the simmiliar problem when I ran the LUALL.exe from the comand promt it download the contents but not from the SEPM. This is due to authentication methods use by SEPM and LUALL.exe.

So if you have a proxy tr to avoide the proxy and hav direct connection from the firewall to the SEPM. Ports needs to be open in the firewall is 80, 443 and optinally 21. Apart fromt that if you can try to create a rule to allow liveupdate.symantecliveupdate.com & liveupdate.symantec.com to come to your AV server IP address.

Those are the things I can think of. Mnday I'll be visting the client side to test the by passing of proxy method. Wish me good luck guys /gals :smileyhappy:

DDPatil's picture
14
Jun
2008
0 Votes 0
Login to vote

Hi Susantha,
 
Thanks for help. I already ByPass the proxy. also I tried without proxy. but it did not work.
Abhishek Pradhan's picture
15
Jun
2008
0 Votes 0
Login to vote

Hi Dattatray,

Recommend that you open a support incident for the same. You'll get a faster resolution that way.


Abhishek Pradhan, PMP, MCT
Consultant | Microsoft Corp.
Blog: http://blog.abhishekpradhan.net | SIG Lead - Pune IT Pro (Microsoft Pune User Group) | http://www.puneusergroup.org

DDPatil's picture
15
Jun
2008
0 Votes 0
Login to vote

Hi Abhishek,
 
Thanks for suggestion. I called up to customer care to open incident, After waiting 1-1.30hrs for two to three calls I did not get chance to speak with them. I do not have time to wait half an hour. 
I got one hope so I can stress. One of my client reported below event
 
Event ID : 13
Source : SescLU
Description :
LiveUpdate returned a non-critical error. Available content updates may have failed to install.
 
After this event I searched for the event ID & found following but that also didn't worked for me.
 
 
pbogu's picture
16
Jun
2008
0 Votes 0
Login to vote

@DDPatil
If ur manager is updating correctly then please check logs on the clients not on the server.
Go through this file for errors:
\Documents and Settings\All Users\Application Data\Symatec\LiveUpdate\Log.LiveUpdate
(that's the path I remeber I'm to lazy to check it now ;) but file name is 100% correct and path is at least very similar)

DDPatil's picture
16
Jun
2008
0 Votes 0
Login to vote

Hi Piyush & Abhishek,
 
Today Morning I got following error in Symantec Manager,
 
June 17, 2008 11:12:40 AM GMT+05:30:  LiveUpdate failed.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 17, 2008 11:12:40 AM GMT+05:30:  LUALL.EXE finished running.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 17, 2008 11:12:40 AM GMT+05:30:  LiveUpdate encountered one or more errors. Return code = 4.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 17, 2008 11:09:34 AM GMT+05:30:  LUALL.EXE has been launched.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
June 17, 2008 11:09:34 AM GMT+05:30:  Download started.  [Site: Site-sv-sug-0002]  [Server: sv-sug-0002]
 
When I run LUALL.exe manually on server, its downloaded virus defination successfully. but again for client its fail.
 
Is this problem with SEM MR2.
 
I am not understadning this stranger behavior of SEP.
 
Hi pbogu
 
I have not found "log.liveupdate" error file in client as well as server. Any way thanks
 
 
 
pbogu's picture
18
Jun
2008
0 Votes 0
Login to vote

That's really strange because LU is creating this file automatically on every run. Is Lu installed on the clients (it should - it's part of the client installation process)?

burningtower's picture
18
Jun
2008
0 Votes 0
Login to vote

The path is "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\log.liveupdate"
Don't know what good it will do you though, on failed updates it often doesn't even get created.
The solution that I found that works is to;
Delete every program on the machine that says "Symantec" (yes, Ghost too)
Delete all the Symantec directories on "C"
Install the client normally
Wait a couple of hours and when it's all installed and updated you can re-install your other apps.
It is a real PITA I know but it's the only thing that seems to work consistantly. I have spent hours on the phone with tech support and I have an open ticket on this. No matter what the techs have me do a couple of days later I'm back in the same hole with the same machines. The above process seems to cure the problem so that it stays cured. If anyone has a better solution I'd sure like to hear it.
DDPatil's picture
18
Jun
2008
0 Votes 0
Login to vote

 
@burningtower, @pbogu
 
Thanks for your mail. I had unistall SEP MR2. and Installed fresh Manager. Before installation of MR2 we need do delete all the content folder also we need to delete virs def. (zip) I don't know exact location. Also I faced client policy serial number issue.Please see attached screen shot for more detail.
 
 
Policy serial number its showing different on client and in server its different.
 
Anyway thanks for your help.
 
 

 
DDPatil's picture
19
Jun
2008
0 Votes 0
Login to vote

After fresh installation of SEP MR2. I had created client packages and deployed on client. Still server is not able to push virus defination to the client. for 1 client green spot appearing with yelllow dot with black exclamation and for 2 client with no spot. but there is no communication issue with client and server. If I issued command from server to shut down for client. It will force the client to shut down.
Now I have openned case for this but After waiting one line I am not able to reach technical person.
 
Hope symantec will release MR3 immm...
 
As I am developer I don't know how symantec is tested this product and released. Also they missing some steps in migration.



Message Edited by DDPatil on 06-19-2008 03:58 AM

Message Edited by DDPatil on 06-19-2008 03:59 AM

burningtower's picture
19
Jun
2008
0 Votes 0
Login to vote

Dattaray,
 
I understand that you installed the new Manager Console. What I was referring to was the clients themselves. You need to un-install the clients, un-install any other programs that say "Symantec", then go through the "C" drive and delete any folders that say "Symantec" (ie; "Symantec Shared") reboot the client machine, and then re-install the client from the Management Console.
 
PS could not see your "screen shot"
DDPatil's picture
19
Jun
2008
0 Votes 0
Login to vote

@burningtower,
 
Thanks for your reply. Basically problem is due to client package has not been modified "Sylink.xml" file. Symantec guy has found this problem he has modified Sylink.xml file and He has given one tool So I can easily deploy this "Sylink.xml" file to each client. After deploying this file my all clients are updating virus definition.
If you any one wants this tool I can share.
 
Thanks for your valuable support & Suggestion.
 
Thanks Symantec for their support
dwienie's picture
20
Jun
2008
0 Votes 0
Login to vote

Hello Dattaray,
It should be nice if you can upload this tool.
What are the modifications in the sylink xml file ?
 
Regards,
Edwin
pbogu's picture
20
Jun
2008
0 Votes 0
Login to vote

Correct me if I am wrong but I believe that the tool is SylinkDrop.

It's available on SEP CD2

CD2\TOOLS\NOSUPPORT\SYLINKDROP

DDPatil's picture
20
Jun
2008
0 Votes 0
Login to vote

Hi
 
The tool which I got from symantec tech. guy which deploy "Sylink.xml" file remotely from the server using Migration and deployement wizard to the client. So we can push Sylink.xml file from server to client. I think this tool is not avilable with CD.
 
However SylinkDrop tool need to run on indiviual client machine to update same file.
 
I have created document for how to deploy Sylink file using Sylink-Remote tool. which is uploaded in my blogs. Also this tool is available at below location under symatec folder.
 
 
I don't know how to upload so I have uploaded in my Space. Please let me know where can I update these type of stuff.
 
Jason1222's picture
20
Jun
2008
0 Votes 0
Login to vote

Thanks DDPatil,
 
I am sure this will help out for many people.  One thing worth mentionning though, the SYLINK.XML contains code specific to your SEPM Server and to the GROUP in which the machine is located.
 
This will work really well if you have 1 group and 1 server OR if you can move the computers to the right group after they have been updated.
 
If you have multiple sites or servers, the SYLINK.XML file should come from a machine connecting to that server and that is in the proper site and be deployed only to that site.
 
If you have many groups, and you already have an idea of how the machines will be distributed into their individual groups, I.E. Accounting, Engineering, HR, IT, etc than you should definitely deploy a few times, using the correct file each time.  This could save you alot of time in havnig to redistribute everyone to where you need them to be.
 
Good doc though.  Thanks again.
DI's picture
21
Jun
2008
0 Votes 0
Login to vote

I have experienced all the issues discussed in this thread.  My install is currently at MR2 MP1 but no clients will update.  The other issues appear to be *finally* resolved.  My question is, where do I get a valid Sylink.xml file to deploy?  I have no "working clients" to copy it from.
DI's picture
22
Jun
2008
0 Votes 0
Login to vote

I tried creating my own package without checking the "create a single .exe file" option.  I then deployed the sylink.xml file from the installation folders to the client by running SyLinkDrop on the client.  None of this worked.  The previous post stated, "the Symantec tech guy modified the sylink.xml file".  What did he modify?
 
Also, the System Log under Client Management shows a connection to the correct SEPM server and then a disconnection 2 seconds later.  There are no errors in the log.
 
Is there a standalone updater that can be downloaded and run on these clients?  At least they would be current until this issue is resolved.
Abhishek Pradhan's picture
22
Jun
2008
0 Votes 0
Login to vote

@ DI -
----------------------------------------------------------------
The previous post stated, "the Symantec tech guy modified the sylink.xml file".  What did he modify?
----------------------------------------------------------------
 
If you modify the sylink.xml file, it will be corrupted. The Sylink.xml is encrypted, so no one can modify the file contents and play havoc with the SEPM infra. I guess DDPatil is confused about the procedure for a Sylinkdrop.
 
I'd recommend you open a support incident, and see firsthand from an engineer who has performed the Sylinkdrop operation a couple of times, so you can get the basic idea, as well as the correct process to follow for a successful Sylinkdrop
 
@ DDPatil -
 
where are you calling from (which country and city)? which number are you calling ? have you opened any case so that the Support Teams can assist you on the same ?
 
PM me the case ID if you have opened one, and i'll see what we can do about that.
 
 



Message Edited by Abhishek Pradhan on 06-22-2008 06:12 PM

Abhishek Pradhan, PMP, MCT
Consultant | Microsoft Corp.
Blog: http://blog.abhishekpradhan.net | SIG Lead - Pune IT Pro (Microsoft Pune User Group) | http://www.puneusergroup.org

DI's picture
25
Jun
2008
0 Votes 0
Login to vote

After logging into MySupport, it wants to "verify" my account before I can submit a trouble ticket.  It is asking for a Technical Contact ID, Support Number or Case ID.  To my knowledge, I don't have any of these.
 
I own 20 clients and my maintenance is current.  I have a serial number and an exended maintenance number.  Please assist.
DDPatil's picture
26
Jun
2008
0 Votes 0
Login to vote

Hey Abhishek,
 
Thanks FYA... Sorry for Late reply as I am busy with my Project Delivery. As you mention about we can not modify Sylink.xml, I am not agree with your point we can modify server address (IP Address) & port number (As per my knoweldge & exps with your product). Your mentioning that its encrypted, but its pure XML file. which contain server & certificate replated information. These are things we cann't modify i.e. domainID, Serverlist, Certificate etc.
As I told earlier Symantec tech support guy has been deployed fresh copy of one client machine (Not contains any symantec related file/applications) and copied that client Syllink.xml file & deployed on every machine using Remote tool.
Now everything working properly ..... :smileyhappy:
 
-Jason thanks for your appriciation.



Message Edited by DDPatil on 06-26-2008 05:57 PM

Abhishek Pradhan's picture
29
Jun
2008
0 Votes 0
Login to vote

Hi Dattatray,

 

------------------------------------------------------------------------------------------

 As I told earlier Symantec tech support guy has been deployed fresh copy of one client machine (Not contains any symantec related file/applications) and copied that client Syllink.xml file & deployed on every machine using Remote tool.

------------------------------------------------------------------------------------------ 

 

You said that the Sylink was modified - and you are also saying that you can change the data, i.e. Servername and IP Address in the Sylink.xml file. Sure, go ahead and do that. Then see what havoc the modifications will play with the client. Your client will show the server as offline, and it'll stay that way, since now the Hash value has changed, AND also because not the server cert. on the client has been corrupted.

 

Please note that there is a BIG difference between a Sylink copied form the relevant SEPM client group, and one that you script. One will be recognized by the Cliene, and one will not.

 

Again a request to stop posting misleading info about the architecture of the AV.

 

 

Abhishek Pradhan, PMP, MCT
Consultant | Microsoft Corp.
Blog: http://blog.abhishekpradhan.net | SIG Lead - Pune IT Pro (Microsoft Pune User Group) | http://www.puneusergroup.org