How do you change the frequency of the virus definitions out of date message?
Created: 08 Oct 2012 | 31 comments
We have a SEPM 12.1 server which manages our SEP 12.1 clients. As a number of these clients do not always log in regularly we often get users calling in as they get the virus definitions are out of date message but when they click ok this message reappears very shortly afterwards. Is there a way to change the frequency that this meesage appears, so for example once an hour or twice a day? We still require the users to get this message, but the amount of times it keeps appearing seems to be excessive and is causing our users to call in unnecessarily.
Thanks.
Discussion Filed Under:
Group Ownership:
Comments 31 Comments • Jump to latest comment
To modify the Antivirus and Antispyware policy's notification settings:
Reference
http://www.symantec.com/business/support/index?page=content&id=TECH150078
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi,
This issue occurs when definitions provided by the Symantec Endpoint Protection Manager are older than the amount of days configured in the Antivirus and Antispyware policy before an outdated definitions notification will appear.
If the definitions on the SEP client and SEPM server are less than 24 hours old, the Antivirus and Antispyware policy is likely configured to warn after definitions are 1 day out of date. This is against best practices as definitions new definitions are not made available immediately at midnight.
Miscellaneous tab is available in Enterprise Edition only, it's not available in Small Business Edition.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Select your AV policy
Miscellaneous >> Miscellaneous tab >> Adjust Display a Windows Security Center message when definitions are outdated
SEP Knowledge Base
Endpoint SWAT
Thanks everyone for your replies.
I have already set the appropriate settings under the miscellaneous policy, however this isn't the problem. We have some clients that have not accessed the network for more than 30 days, but I don't want to chnage the notification to alert for out of date definitions longer than that.
The problem we have is that when a client does receive the notification they only have the option to click 'close' and when they do they get another prompt about 30 seconds later, even though the client is in the process of updating. This is causing great annoyance to some of our users which is why I want to modify the frequency of this alert so they will only get the prompt again if the client hasn't updated within a specified amount of time (eg 1 hour).
Hi,
I think this option are not available in SEPM you can Set Specify Amount of time.
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
The original post is experiencing and issue where pressing OK on the "out of date" message doesn't actually make the message go away. It keeps popping up immediately after pressing OK.
I experience this issue too on 12.1 MP1 RU1. I didn't experience it before upgrading to this latest release. I'm hoping this issue is resolved in 12.2.
We have also had the same problem when running 12.1 RU1 MP1. The notification does not suppress for 24 hours like previously in SEP 11. I had a case with support who told me to change my out of date notifications to 28 days, that does not work in my enviroment.
SEP 11 used to have the option to "not remind me for another 24 hours" which was generally plent of time for the GUP or Live Update to push out the definitions. Since support does not seem to remember this feature I have turned it off on the client end, and monitor it from the SEP Manager and vulnerability scanner.
Hello,
I would suggest you to edit the "Virus Definitions Out-of-Date" Notification and set the correct Damper Period and correct settings.
Damper Period:
Specifies the length of the damper period, in minutes or hours, that you want to use for this notification.
Some logs use a damper period for event aggregation. Events are held on the clients for the damper period before they are aggregated into a single event and then uploaded to the console. The damper period helps to reduce events to a manageable number.
The default damper setting is Auto (automatic). If a notification is triggered and the trigger condition continues to exist, the notification action that you configured is not performed again for 60 minutes. For example, suppose you configure a notification to alert you when a virus infects five computers within one hour. If a virus continues to infect your computers at or above this rate, you receive notifications every hour. The notifications continue until the rate slows to fewer than five computers per hour.
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
This isn't an issue with notifications to the Symantec administrator. These pop ups are happning on the SEP clients.
Hi,
Could you please check the damper settings.
Navigation path:
SEPM --> Monitors --> Notifications --> View Notifications --> Notifications Conditions --> Edit Virus Definitions out of date --> Check damper setting time, I hope it's not set to Auto.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Thanks Chetan,
I have checked the above settings you have advised and the Damper setting time is 10 hours - (not set to auto).
However am I not correct in understanding that this setting relates to notifications on the server, not on the client itself?
Hi,
You are correct, these settings are relates to notification on the server.I was just co-relating it.
Can you move all those clients to a new group and disable notification pop up on that group.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Thanks Chetan,
I could move them, but this does not resolve the issue. I still want them to receive notifications but I want to reduce the frequency of the pop-ups.
Hello,
There is no such settings under notification where you could specifically reduce the frequency of the pop-ups.
Hope that helps!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
Hi,
I don't see any such settings under notification where you could specifically reduce the frequency of the pop-ups.
I am not able to find any registry tweak as well
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Just out of curiousity, has anyone done a complete uninstall/reinstall? Did that fix it?
SEP Knowledge Base
Endpoint SWAT
HI,
This setting not available in SEPM ,
You can raised Idea for this option
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
What is that "Damper" means ?
Kind regards,
John Santana
IT Professional
--------------------------------------------------
Please be nice to me as I'm newbie in this forum.
Hi John,
Damper settings is very interesting concept.
You can set a damper period for notifications. The damper period specifies the time that must pass before the notification condition is checked for new data. When a notification condition has a damper period, the notification is only issued on the first occurrence of the trigger condition within that period. For example, suppose a large-scale virus attack occurs, and that there is a notification condition configured to send an email whenever viruses infect five computers on the network. If you set a one hour damper period for that notification condition, the server sends only one notification email each hour during the attack.
Reference: http://www.symantec.com/docs/HOWTO55051
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
I have been bombarded with Unamanged Notification list email (about 100 of them) since I put it 10 minutes.
Thanks for pointing this out man
Kind regards,
John Santana
IT Professional
--------------------------------------------------
Please be nice to me as I'm newbie in this forum.
Not even encountered in my present Administration of SEP. To avoid annoyance to client, disable all the pop-ups and refer to the logs for your reference.
Thanks everyone for your responses. Your solution, Ch@gGynelL_12, is OK as a workaround, however we do want the clients to be notified if virus defs are older than 30 days, so will keep the alerts on. This is in case anything is missed in the logs or a client drops out of SEPM without us realising (this has happened before with 2 pcs with the same hardware id). The client side alert at least will prompt user to call if there is a problem. It seems that we have to accept there is no way to configure this, which is a shame and seems to be an oversight in the design of SEP 12.1. Maybe next release will include this feature as the lack of it will potentially cause a lot of calls to service desks when there are a lot of clients deployed in a SEP environment.
When they get the message, are your users checking the box that says "Don't remind me again until after the next update"? If not, have them give that a try.
In which version of SEP do you see this checkbox? Thanks.
sandra
Symantec, Information Development, IMDP
Symantec Endpoint Protection / Core Security Engineering Group
Don't forget to mark your thread as 'solved' with the answer that best helped you!
I think it's been there since the SAV days. This is the notification on the client.
Yes, that is correct, I guess this is harmless since the SEP client AV definitions will be downloaded soon after it talks back to the SEPM server.
Kind regards,
John Santana
IT Professional
--------------------------------------------------
Please be nice to me as I'm newbie in this forum.
Thanks. In SEP (12.1.2 enterprise version), I can confirm that a.) there is no way to define a period of X minutes/days before the next notification occurs, but b.) that the "Don't remind me again until after the next update" check box is still there in the client-side pop-up notification.
(I would think that this same checkbox is present in Small Business Edition, too, but I didn't get to check that directly.)
sandra
Symantec, Information Development, IMDP
Symantec Endpoint Protection / Core Security Engineering Group
Don't forget to mark your thread as 'solved' with the answer that best helped you!
On a vaguely related note, have you considered using Location Awareness (http://www.symantec.com/docs/TECH97369) so that your SEP clients obtain the latest definitions directly from Symantec LiveUpdate when they are out of the office.
While this doesn't directly affect the notifications themselves, it would prevent the "Defs out of date" message from appearing, as the clients will be up-to-date. Plus, you'll have the added security of ensuring your client machines are using the latest defs where ever they are (clearly this is only applicable if the out of office laptops have access to the Internet).
http://www.cstl.com/
(clearly this is only applicable if the out of office laptops have access to the Internet).
.....and there is no proxy setting to use outside the office.
Kind regards,
John Santana
IT Professional
--------------------------------------------------
Please be nice to me as I'm newbie in this forum.
Hello,
It has been found that the option "Don't remind me again until after the next update" is visible only if the logged user has admin priviledges and UAC is disabled.
Regards,
Giuseppe
Quote: It has been found that the option "Don't remind me again until after the next update" is visible only if the logged user has admin priviledges and UAC is disabled.
Does anyone know if 12.1.2 or 12.1.2.1 has fixed this issue or is it still outstanding? Thanks-
Would you like to reply?
Login or Register to post your comment.