Endpoint Protection

 View Only
Expand all | Collapse all

Live updates received, but not appearing on SEPM 12.1.3001.165

  • 1.  Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 29, 2013 03:59 PM

    We recent moved SEPM 12.1.3001.165 from the C drive to the D drive on our Windows Server 2008 R2 Standard. Everything looked fine with the exception of the LiveUpdates not being reflected on the SEPM, and therefore not being pushed out to client workstations.

    Our Server is communicating with Symantec and receiving the LiveUpdates:

    QCC_LiveUpdateStatus_0.png

    QCC_LiveUpdates.png

    However, these are not showing up in SEPM:

    QCC_WindowsDefinitions_SEPM1.png

    QCC_LiveUpdatesRecentDownloads1.png

     

    Any ideas or suggestions as to what the problem may  be? Let me know if there are any further details that can be provided.

    Thank you.

     

    90px_QCC_LiveUpdateStatus.png

     



  • 2.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 29, 2013 08:20 PM

    it might have tried to update and failed. The screen shot from SEPM shows the last AV download was on September. You can try these two steps

    1. Clear all the corrup defs and run Lucatalog cleanup

    http://www.symantec.com/business/support/index?page=content&id=TECH166923

    2. Uninstall / reinstall LU

    http://www.symantec.com/business/support/index?page=content&id=TECH171060

    if it fails post the Liveudpate log

    http://www.symantec.com/business/support/index?page=content&id=TECH171060



  • 3.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 30, 2013 11:43 AM

    I'd recommend reviewing the below article on troubleshooting LiveUpdates on the SEPM:

    http://www.symantec.com/docs/TECH105924

    I've always found it very useful in troubleshooting such issues.  I do have a couple of questions though:

    • How did you do perform the move?
    • The screenie of the folder contents appears to be a LiveUpdate Administrator folder rather than the SEPM's own LiveUpdate Client folder.  Can you confirm if the LUA is installed on this box as well?

    IF LUA is on this box, then the first recommendation is to investigate removing it, as Symantec recommend against having them both on the same box:

    http://www.symantec.com/docs/TECH93409

    Also, just because the LUA is downloading correctly, doesn't necessarily mean that it is distributing correctly, nor that the SEPM is connecting correctly to the LUA's distribution Centre.

    My first port of call would be to review the SEPM's source servers (under ADMIN -> Servers -> highlight Local Site -> click Edit Site Properties -> Liveupdate tab -> Source Servers), and point this at the Default Symantec LiveUpdate servers, if not already there.  Then try another update, and have a look at the log.liveupdate and sesmlu.log files for errors shoudl this continue to fail (locations for these files are in first article link).



  • 4.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 31, 2013 02:15 PM

    reposted as reply



  • 5.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 31, 2013 02:15 PM

    Hi SMLatCST,

    How did you do perform the move?

    https://www-secure.symantec.com/connect/forums/out-disk-space-sepm-move-sepm-another-drive

    Steps:

    (1)  Use the Symantec Endpoint Protection “Database Back Up and Restore” utility to take a backup of the SEPM environment including the Log Files. This will do a couple of things:

    a. Create a backup of the database which will be stored at C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\backup\*.zip

    b. Create 2 backup files that contain the Private Key for the server.  These files will be labeled “keystore_’date & version of backup here’.jks” and “server_’date & version of backup here’.xml”.  These files will be located at C:\Program Files\Symantec\Symantec Endpoint Protection Manager\Server Private Key Backup\

    (2 )  All of these files should be copied to a location that is easily accessible at a later time.

    (3)  Uninstall Symantec Endpoint Protection Manager from the Server.

    (4)  Restart the server.

    (5)  Install the Symantec Endpoint Protection Manager on the desired Drive, using the same installation media version that you just uninstalled from the C: Drive.

    (6)  When the Configuration Wizard launches at the end of the Installation, accept most of the standard settings. If your old installation used a SQL DB, make sure that you configure the DB setting to connect to the original database.  This will of course remove your old configuration from the DB, but that’s why we have a back-up.

    (7)  Copy the database backup file to <Install Drive>:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\backup\.

    (8)  Stop the Service titled “Symantec Endpoint Protection Manager”

    (10)  Launch the “Database Back Up and Restore” utility, except this time select “restore” from the main menu; when asked which version to restore, select the one that was just copied to the new SEPM installation path.

    (11) Once the restore is complete rename and copy the 2 key backup files to :

    server_’date & version of backup here’.xml” – <Install Drive>:\Program Files\Symantec\ Symantec Endpoint Protection Manager\tomcat\conf\server.xml

    keystore_’date & version of backup here’.jks” – <Install Drive>:\Program Files\Symantec\ Symantec Endpoint Protection Manager\tomcat\etc\keystore.jks

    (12)  Run the “Management Server Configuration Wizard” to ‘Reconfigure’ the database, making sure to point it to the same database as was used previously.

    (13)  After the reconfiguration is complete, the SEPM Console will launch automatically. You should now be able to log in as you have always done using your security accounts. The Console should indicate that it is communicating and managing the clients that were being managed prior to the SEPM Move.

     

    The screenie of the folder contents appears to be a LiveUpdate Administrator folder rather than the SEPM's own LiveUpdate Client folder.  Can you confirm if the LUA is installed on this box as well?

    There are LiveUpdate folders located here:

    C:\Users\All Users\Symantec\LiveUpdate

    C:\ProgramData\Symantec\LiveUpdate

     



  • 6.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 31, 2013 02:16 PM

    Thank you Rafeeq!

    I will try your suggestions.



  • 7.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Oct 31, 2013 02:16 PM

    Reposted as reply



  • 8.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 01, 2013 06:33 AM

    Hi

    What is the database you are using

    Regards

     



  • 9.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 01, 2013 06:47 AM

    lol, just saying DR method would have been fine wink

    In that case, I'd highly recommend you follow the first link I posted, as this is pretty good for troubleshooting SEPM Updates.

    The crucial bits to pay attention to will be reviewing the log.liveupdate and sesmlu.log files for errors.



  • 10.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 01, 2013 10:02 AM

    Embedded



  • 11.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 01, 2013 10:43 AM

    One thing I noticed was on the Local Site, the Creation Time is listed as July 18, 2013. The reinstall was executed on September 18, 2013. Shouldn't the date be September 18, 2013? And if so why would it be pointing to the older date?

    QCC_LocalSite.png



  • 12.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 02, 2013 01:03 PM

    Hi

    Can you check in Server.xml whether there are two sites mentioned

    Regards

     



  • 13.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 04, 2013 09:26 AM

    Where would the Server XML be located?



  • 14.  RE: Live updates received, but not appearing on SEPM 12.1.3001.165

    Posted Nov 04, 2013 03:31 PM

    Hi,

    Agreed with Sameer.

    You didn't mention if you're using Embedded or SQL Database which is very important in order to orient you efficiently where you should look at and how to fix it.

    If it's SQL Database, have a look on the scm.server-0.log you may find obvious error related to SQL Db (fg_content group file full for example. Very common that one).

     

    Edit: Nvm I wasn't able to see the previous screenshot. Embedded ok ;)

     

    Kind regards,

    A. Wesker