Endpoint Protection

 View Only
Expand all | Collapse all

Duplicate Definition Folders under SEP 12.1.2

  • 1.  Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 12:14 PM
      |   view attached

    Hello folks -

    An app owner brought this to my attention this morning stating that SEP is holding on to duplicate definition files and taking up space that they can use on their servers. I was wondering if someone could help me understand why SEP does it and if there is a way to eliminate this issue all together.

     

    SO under take a look at this screenshot as you can see CurrenVersion folder contains the same defs as the Data/Definition/VirusDef folder.

     

    Can anyone clarify why is that the case please and if there is a way to remove a duplicate?

     

    many thanks!



  • 2.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 12:20 PM

    SEP 12.1 should only be keeping 1 content revision for AV content:

    Configuring the number of content revisions kept by the Symantec Endpoint Protection client

    Article:TECH103956  |  Created: 2008-01-15  |  Updated: 2012-10-08  |  Article URL http://www.symantec.com/docs/TECH103956

     

    The definitions set may be corrupt and you can try clearing out:

    How to clear out definitions for a Symantec Endpoint Protection 12.1 client manually

    Article:HOWTO59193  |  Created: 2011-09-08  |  Updated: 2012-09-25  |  Article URL http://www.symantec.com/docs/HOWTO59193

     

    Was this a fresh install of 12.1 or and upgrade from 11.x?



  • 3.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 12:23 PM

    Thanks this was a an uprade from 12.1 to 12.1.2, but I am seeing similar issue on my desktop also.

     

    So most of the machines are showing same definitions and have identical files Under Current Version Vs just Data\Definitions\VirusDefs why 2 copies is my question?

     

     



  • 4.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 12:25 PM


  • 5.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 12:34 PM

    Do not use Rx4DefsSEP on a 12.1 client. Below is a quote taken from the KB.

     

    "It is not intended for operation with Symantec Endpoint Protection 12.1 systems due to changes in folders and operations"



  • 6.  RE: Duplicate Definition Folders under SEP 12.1.2
    Best Answer

    Posted May 22, 2013 12:49 PM

    The CurrentVersion folder is a junction to the actual version number of the installed SEP client, in your case 12.1.2015.2015.

    Make a change in the 12.1.2015.2015 folder and it is reflected in the CurrenVersion folder, it's not a duplicate, it's the same file referenced twice because of the junction.

    #EDIT#

    You can confirm this by running the below command:

    junction.exe -s "C:\ProgramData\Symantec\Symantec Endpoint Protection"

    Using the junction tool from MS below
     
    On my machine, it shows the below results:
     
    \\?\C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion: JUNCTION
       Substitute Name: C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105

    #EDIT2#

    This is also why the CurrentVersion folder has a little shortcut icon on it!



  • 7.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 01:01 PM

    Clear the defintion from Server and check

    How to clear corrupt Virus Definitions from SEPM
    https://www-secure.symantec.com/connect/articles/how-clear-corrupt-virus-definitions-sepm

    http://www.symantec.com/docs/TECH166923



  • 8.  RE: Duplicate Definition Folders under SEP 12.1.2

    Broadcom Employee
    Posted May 22, 2013 01:02 PM

    thumbs up SMCatCST!

    use the tool it will show the information as posted above.



  • 9.  RE: Duplicate Definition Folders under SEP 12.1.2
    Best Answer

    Posted May 22, 2013 01:24 PM

    Answer to my question as given to me by our SME is:

     

    The reason you see two copies is the currentversion is actually a junction point linking the directory to \symantec\symantec endpoint protection\<SEP version>. From a command prompt, cd to the Symantec endpoint protection directory and run dir – XP/2003 should list <junction> instead of <dir> - newer operating systems will also list the actual directory being linked and will show the arrow on the folder within Windows explorer.

     

    Thanks all for your responses.



  • 10.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 01:32 PM

    Can you please mark the post by SMLatCST as the solution? I think his answer is best suited in this case.



  • 11.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 02:10 PM

    Apoligies I did not see that post when I did the refresh. Made his a solution. Thx alot guys for all ur assistance.



  • 12.  RE: Duplicate Definition Folders under SEP 12.1.2

    Posted May 22, 2013 02:18 PM

    Thanks!