Endpoint Protection

 View Only
  • 1.  Linux client scan settings in SEP 12.1.6168

    Posted Jun 22, 2015 07:14 PM

    I have a headless Ubuntu server that I am trying to setup with SEP protection. I have a few questions regarding configuration/settings.

     

    1) When I go into the SEP Manager on the server to initiate a scan on the Ubuntu client I get 3 choices of Active, Full, or Custom, with the first 2 marked as Windows only. I choose Custom - "Scan selected hard drives or network drives", but I am never prompted to select drives. Where is this selection made?

    2) Command Status under Monitors shows the custom scan completed with Supplementary details noting some 300k files scanned. Where can I view a list of paths/files that were scanned?

    3) Why does the Linux client's syslog show current complaints from symev if the scan has already completed?

    4) The Linux client's syslog shows errors such as symev: cannot get valid inode for /proc/net/rpc/nfsd. I get a log entry like this every 15 seconds or so. Doesn't SEP know to only scan "real" files? Is there a default Linux excludes list that I need to install or something?



  • 2.  RE: Linux client scan settings in SEP 12.1.6168

    Posted Jul 12, 2015 09:43 AM

    My suggestion would be to engage support if you have not gotten this solved yet.