Protection Engine for Cloud Services

 View Only
Expand all | Collapse all

Liveupdate from central server reports succes, however still need to copy definition files manually

  • 1.  Liveupdate from central server reports succes, however still need to copy definition files manually

    Posted Apr 04, 2016 08:13 AM

    Hello,

    We have SPE running on Linux (Suse v11.3). Virus definitions are downloaded from a central liveupdate server. The liveupdate logfile reports success:

    10:22:04.053774 [Session Results - START]
    10:22:04.053825 Session Result Code: 0x00010000
    10:22:04.053844 Session Result Message: OK
    10:22:04.053858 [Component Result - START]
    10:22:04.053874 Component ID: {BAE8FC84-53DC-11E1-8A6B-005056A9534A}
    10:22:04.053889 Display Name: SPE 7.5 AV Definitions for x86-linux
    10:22:04.053906 PVL: SPE 7.5 AV Definitions for x86-linux_MicroDefsB.CurDefs_SymAllLanguages
    10:22:04.053923 Result Code: 0x00010000
    10:22:04.053937 Result Message: OK
    10:22:04.053952 [Package Result - START]
    10:22:04.053965 File: 1459455297jtun_csapilinencful.m35
    10:22:04.053981 Result Code: 0x00011003
    10:22:04.053994 Result Message: UNKNOWN
    10:22:04.054008 [Package Result - END]
    10:22:04.054021 [Component Result - END]
    10:22:04.054035 [Session Results - END]
    10:22:04.054048 [Session Summary - START]
    10:22:04.054061 Components: 1
    10:22:04.054074 Packages: 1
    10:22:04.054087 Success: 1
    10:22:04.054100 Fail: 0
    10:22:04.054113 [Session Summary - END]
    10:22:04.054126 ********************************************************************************
    10:22:04.054151 Session ended at Fri 2016/04/01 10:22:04 (UTC +0200)
    10:22:04.054165 ********************************************************************************

    However, the virus definition date in the admin console was not updated. After some searching we found a directory:

    /opt/Symantec/symcdata/csapi_defs/20160331.001

    with the downloaded virus defintion files. We decided to copy these manually to directory:

    /opt/SYMCScan/bin/definitions/AntiVirus/VirusDefs 

    Now the virus definition date in the admin console was updated with the correct defintion date. However, I do not want to make manually copying the virus defintion files part of our daily SPE manintenance procedure, so what is wrong here: why are thos files downloaded but not placed in the right directory?



  • 2.  RE: Liveupdate from central server reports succes, however still need to copy definition files manually

    Posted Apr 04, 2016 08:29 AM

    test