Endpoint Protection

 View Only
Expand all | Collapse all

How can I know whether my sepm server is sending incremental updates to client or full update.

  • 1.  How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 22, 2012 10:49 AM

    How can I know whether my sepm server is sending incremental updates to clients or full update.No live update server .

    which clients are getting incremental updates and which are gettting fulll update.



  • 2.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Broadcom Employee
    Posted Mar 22, 2012 11:03 AM

    Hi Bijay.Swain,

    Run Sylink monitor tool on clients, Sylink log can tell us whether it's delta update or full update.

    You can not check it through SEPM.

    Ideally detla updates are very small compare to full update. Network monitor tools may help you to check traffic between source and destination. If clients are requesting full.zip then you will definitely see more bandwidth utilization.

    I hope it answer your question.



  • 3.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Trusted Advisor
    Posted Mar 22, 2012 11:21 AM

    Hello,

    I would recommend you to check these Articles:

    Symantec Endpoint Protection clients download full definitions from Group Update Provider or from Symantec Endpoint Protection Manager

    http://www.symantec.com/docs/TECH122612

    Symantec Endpoint Protection Manager Auto-Upgrade using RU6/RU6a Manager pushes full client instead of delta

    http://www.symantec.com/docs/TECH137774

    With default LiveUpdate content revision settings configured within the Symantec Endpoint Protection Manager, clients are downloading full definition updates instead of delta updates

    http://www.symantec.com/docs/TECH94916

    Hope that helps!!



  • 4.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 22, 2012 02:36 PM

    Will try the sylink monitor tool.

    thanks for your reply



  • 5.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 22, 2012 02:40 PM

    Hi Mithun

    Thanks for the useful links. will test some  of the tricks in these documents.



  • 6.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 22, 2012 02:51 PM

    Additionally, you could try the SEP Content Distribution Monitor. Among other useful things it shows the daily number of the full and delta downloads, together with their bandwidth consumption. You get it here:

    https://www-secure.symantec.com/connect/downloads/sep-content-distribution-monitor



  • 7.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 23, 2012 10:52 AM

    Thanks For the tool



  • 8.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Broadcom Employee
    Posted Mar 23, 2012 11:01 AM

    check the IIS Logs as well.



  • 9.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 24, 2012 08:07 AM

    Hi,

    the sylink.log is a client side log, by enabling it, you can see if a specific client is asking or not for deltas.

    According to your post, you want to find which clients are getting deltas and which clients are getting the full content hence the sylink.log from all clients is not the feasible solution for you.

    IIS logging will record all clients' requests, in your case you need to log the visits only for the Content virtual folder. Once you have it, you may open it in Excel and filter what you need, count repeated events, etc. The difficult part is that you need to know what to look for (monikers, type of files, etc.), something not very easy to explain in a forum.

    While analyzing the IIS logs in regards of the content files, you need to focus on two main things:

    1) of those clients which are getting a specific type of content (example: content\{C60DC...}\120323001 which means 32 bit AV defs 23-03-2012 r001) only once, how many get the delta (.dax if I remember well) and how many the full.zip?

    It is expected that most of the clients get the delta, there is no ideal ratio for everybody, if your specific network or link is overloaded by SEP traffic, you need to decrease the delta/full ratio. This ratio is controlled by the amount of content releases you keep stored in your SEPM.

    Some releases of SEPM soffer of performance issues and cannot create the deltas even when expected. Upgrade SEPM and use GUPs is recommended.

    2) are there clients which are repeating the same exact download over and over again? and always the full.zip even if not always for the same content release?

    If yes, those clients should be locally analyzed for:

    - corrupted definitions (SEP Support Tool checks for it)

    - old SEP releases with known issues (sylink.log might help to find known errors)

    - GUP with small cache that needs to download again the same content to serve different clients (debug.log shows if the GUP is using or not the cache)

    - lack of disk space (<400 MB of free space)

    - virus infection that damage the definitions (see risk logs).

     

     

     



  • 10.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.

    Posted Mar 28, 2012 06:18 AM

    Hi

        How to enable IIS log and debug logs how to analyze it. Is ther any tool to create reports from these logs ?



  • 11.  RE: How can I know whether my sepm server is sending incremental updates to client or full update.