Endpoint Protection

 View Only
Expand all | Collapse all

Definitions not updating, but machines are online

  • 1.  Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:33 PM

    We have VDIs that are stuck on the definitions they had from their parent VM. I'm wondering if there is a setting that disables definition downloads when no users are logged in. 

     

    I know there is a a setting somewhere about scanning with or without a user logged in, is there one similar for definition downloads?



  • 2.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:37 PM

    That should not matter, has anything else changed?

    See here:

    Troubleshooting Content Delivery to the Symantec Endpoint Protection client



  • 3.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:40 PM

    it wil dowmload even if no one is logged in

    check this

    Best Practices for Symantec Endpoint Protection on Citrix and Terminal Servers

    http://www.symantec.com/business/support/index?page=content&id=TECH91070

    Symantec Endpoint Protection 12.1 - Virtualization Best Practices

    http://www.symantec.com/business/support/index?page=content&id=TECH173650



  • 4.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:44 PM

    Enable Sylink Debuggin on the client, will get to know the reason.

    http://www.symantec.com/business/support/index?page=content&id=TECH104758



  • 5.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:47 PM

    Note that this is only happening on a portion of a VDI pool, not all of them. The definitions for a lot of these are stuck on the date the parent was last "recomposed" and they are actively checking into the SEPM (within the last 1 hour).



  • 6.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 12:50 PM

    sylink debugging will give a better look into the problem



  • 7.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 02:26 PM

    Enable sylink debug on one of affected clients: http://www.symantec.com/docs/TECH104758 - the log will show you if there are any errors during client-> sepm communication or definition download.



  • 8.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 03:26 PM

    I turned on Sylink debug on my local machine to test the process. It is not creating the log file. What do I need to do to get that to generate? I'm just trying to write to C:\temp\sylink.log.



  • 9.  RE: Definitions not updating, but machines are online

    Posted Feb 25, 2014 03:29 PM

    did you do smc -start after changing the registry?

    click on update policy, it should starting writing the log



  • 10.  RE: Definitions not updating, but machines are online

    Posted Feb 26, 2014 09:59 AM

    Still nothing after a reboot. Let me check the permissions on C:\Temp

     

     



  • 11.  RE: Definitions not updating, but machines are online

    Posted Feb 26, 2014 10:08 AM

    try c:\sylink.log

     



  • 12.  RE: Definitions not updating, but machines are online

    Posted Feb 26, 2014 11:09 AM

    Ok; I had the new string value in {HKLM...SYLINK} instead of {HKLM...SYLINK\Sylink} and now it is working.

    Now I just need to get on one of the customer machines and enable this.



  • 13.  RE: Definitions not updating, but machines are online

    Posted Feb 27, 2014 02:52 PM

    Just a follow up, it looks like the randomization window on these machines is too large (+/- 4 Hours). These are non persistent VDIs and are only online for ~ 1 hour or so, so many of them are still on the definitions of the Parent VM, and don't update before logging off and "evaporating". 

     

    Since these are VDI we are nervous about changing the randomization window (2000+ virtual machines in scope). I'll let you know what this looks like when we down size the window to +/- 30 Minutes in testing. Hopefully clients get up to date a lot faster, even if they are non persistent and will "evaporate" after shutdown.