Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Filter offline computer accounts

Created: 25 Mar 2013 | 11 comments

In report "Client Online Status Computer Status Report"
We can see a chart for percentage of online/offline computer and related group name.
Can we get a report with specific offline computer name and related group? So that we don't need to logon SEPM to find out the computer

If there is no similiar report available, what's the fatest way to get the offline computer account with related group name ?

Operating Systems:

Comments 11 CommentsJump to latest comment

SMLatCST's picture

 

IIRC, there are only two reports that include the additional "per group" filter, but as I'm sure you've found, neither provide specific machine names.

The closest I can think of to match you requirements, if to create a Computer Status - Client Inventory Details report, with filters set for "Online Status = Offline" and create one filter and scheduled report for each group.

Alternatively, you could look into either SQL queries or IT Analytics to see if they can cover your use case.

W007's picture

look this public kb

 

How to create a SEPM Custom Scheduled Report for Offline SEP Clients.

Article:TECH175948  |  Created: 2011-12-01  |  Updated: 2011-12-01  |  Article URL http://www.symantec.com/docs/TECH175948
 

 

 

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

AjinBabu's picture

Hi,

KB article TECH175948  is applicable for you,

Please have a look.

And Via DB queries also you can also do the same

Regards

Ajin

Rafeeq's picture

Try this

Monitors - Logs - computer status

click on Advanced at the bottom select Online status as Offline.

You will get the report with virus defs / groupname.. you can later filter these out with excel.

SymQNA's picture

1. Many thanks for your assistance to provide the steps, I can filter the offline computer refer to your steps, but I found there is no column indicate the machine is offline. or need to find this info in exported report?

2. I found there is a column STATUS in table SEM_AGENT. May I know if value “1” is ONLINE,valude “0” is OFFLINE

3. What will cause the offline status?

K33's picture

 

1 I found there is a column STATUS in table SEM_AGENT. May I know if value “1” is ONLINE,valude “0” is OFFLINE

Found Database Schema

Symantec™ Endpoint Protection Manager Database Schema Reference
Article: DOC4935
Article URL http://www.symantec.com/docs/DOC4935

Symantec™ Endpoint Protection Manager Database Schema Reference 12.1
Article: DOC4324   |  Created: 2011-06-27   |  Updated: 2012-04-23   | 
Article URL http://www.symantec.com/docs/DOC4324

2. What will cause the offline status?

https://www-secure.symantec.com/connect/forums/wha...

SymQNA's picture

The answer does not help.
Please advise which column indicates SEP client is offline in log report filtering by monitor -> log - > computer status

SymQNA's picture

I test to uninstall SEP on one managed client. It is offline status. but in the log report the Auto-Protect Enabled column still indicate it is Enabled.

offline report.png
Rafeeq's picture

1 is online

0 is offline

the client is offine , So no logs were sent to SEPM. So its showing previous status of the client

K33's picture

Hi,

Computer Status report not showing offline client status.

 

The Computer Status log contains information about the real-time operational status of the client computers in the network.

Available information includes the computer name, IP address, infected status, protection technologies, Auto-Protect status, versions, definitions date, user, last check-in time, policy, group, domain, and restart required status.

You can perform the following actions from the Computer Status log:

  • Scan

    This command launches an Active, Full, or Custom scan. Custom scan options are those that you have set for command scans on the Administrator-defined Scan page. The command uses the settings in the Antivirus and Antispyware Policy that applies to the clients that you selected to scan.

  • Update Content

    This command triggers an update of policies, definitions, and software from the Symantec Endpoint Protection Manager console to the clients in the selected group.

  • Update Content and Scan

    This command triggers an update of the policies, definitions, and software on the clients in the selected group. This command then launches an Active , Full, or Custom scan. Custom scan options are those that you have set for command scans on the Administrator-defined Scan page. The command uses the settings in the Antivirus and Antispyware Policy that applies to the clients that you selected to scan.

  • Cancel All Scans

    This command cancels all running scans and any queued scans on the selected recipients.

  • Restart Client Computers

    This command restarts the computers that you selected. If users are logged on, they are warned about the restart based on the restart options that the administrator configured for that computer. You can configure client restart options on the General Settings tab of the General Settings dialog box on the Policies tab of the Clients page.

  • Enable Auto-Protect

    This command turns Auto-Protect on for all the client computers that you selected.

  • Enable Network Threat Protection

    This command turns on Network Threat Protection for all the client computers that you selected.

  • Disable Network Threat Protection

    This command turns Network Threat Protection off for all the client computers that you selected.

You can also clear the infected status of computers from this log.

 

http://www.symantec.com/business/support/index?pag...