Performing Liveupdate does not complete - "Times Out"
Updated: 21 May 2010 | 18 comments
When I run the LIVE UPDATE or I would guess that when it runs on it's own, it never completes. After a long period of time it cancels the attempt and fails. I'm quite sure it's a firewall related issue, as it is holding all of the downloads until it's complete before continuing.
Is there a way to extend the time on how long the process will download before failing?
Thanks, Jim
SEP 11.4000.2295
discussion Filed Under:
Comments
Re;
Are you using a proxy? Can you provide live update logs?
I have attempted to turn off
I have attempted to turn off and on the proxy client, neither seems to make a difference. I've got the "Microsoft Firewall Client for ISA Server". Generally speaking, it seems to be better when it is enabled as I can see more sites.
Here's my log.
April 7, 2009 11:32:55 PM CDT: LiveUpdate retry failed. Will try again. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:32:55 PM CDT: LUALL.EXE finished running. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:32:55 PM CDT: LiveUpdate encountered one or more errors. Return code = 4. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:28:45 PM CDT: LUALL.EXE has been launched. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:28:45 PM CDT: LiveUpdate retry started. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:13:44 PM CDT: LiveUpdate failed. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:13:44 PM CDT: LUALL.EXE finished running. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:13:44 PM CDT: LiveUpdate will start next on Wednesday, April 8, 2009 3:13:44 AM CDT on Endpoint-SVR. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:13:44 PM CDT: LiveUpdate encountered one or more errors. Return code = 4. [Site: My Site] [Server: Endpoint-SVR]
April 7, 2009 11:09:17 PM CDT: LUALL.EXE has been launched. [Site: My Site] [Server: Endpoint-SVR]
Hi,
Paste logs when proxy client is on and off so that we can compare.
Log Info
ISA proxy disabled.
April 8, 2009 12:26:37 AM CDT: LiveUpdate failed. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:26:37 AM CDT: LUALL.EXE finished running. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:26:37 AM CDT: LiveUpdate encountered one or more errors. Return code = 4. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:21:59 AM CDT: LUALL.EXE has been launched. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:21:59 AM CDT: Download started. [Site: My Site] [Server: Endpoint-Svr]
ISA proxy enabled.
April 8, 2009 12:12:01 AM CDT: Retry timestamp is over the maximum retry window, switching to regular schedule run. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:12:00 AM CDT: LiveUpdate retry failed. Will try again. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:12:00 AM CDT: LUALL.EXE finished running. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:12:00 AM CDT: LiveUpdate encountered one or more errors. Return code = 4. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:07:32 AM CDT: LUALL.EXE has been launched. [Site: My Site] [Server: Endpoint-Svr]
April 8, 2009 12:07:32 AM CDT: LiveUpdate retry started. [Site: My Site] [Server: Endpoint-Svr]
Hi Yes you can increase the
Hi
Yes you can increase the timeout for the liveupdate. To do so Please follow the steps mentioned below.
1.Browse to the drive where your LiveUpdate is installed (c:\ProgramFiles\Symantec\LiveUpdate)
2. Delete the 1.Settings, 2.Settings and all the No.Settings files.
3. Open the default.settings and find PREFERENCES\INTERNET_CONNECT_TIMEOUT=45
PREFERENCES\INTERNET_READ_DATA_TIMEOUT=45, and change 45 to 600.
4. Make sure settings.default file is not read only otherwise you will not be able to save the settings in that file.
5. Save the file.
6. Close the window and run the LiveUpdate.
Here you are through it.
Regards
Ajit
Regards'
Ajit Jha
Technical Consultant
STS
Didn't seem to work
I made the changes, but it still timed out. Should I have to stop and restart the SEP service?
Here is a snapshot of the SESMLU.log file, I don't know if this is the right log or if there is one that is more specific.
0Apr 08 09, 04:13:21 AM INFO(Med) ProductUtil: Response code: 0x0Apr 08 09, 04:13:21 AM INFO(Med) SesmLu: Server successfully published LU inventory.Apr 08 09, 04:13:21 AM INFO(Med) SesmContentCatalog: Entered Init().Apr 08 09, 04:13:21 AM INFO(Low) ProductUtil: Data root = C:\Program Files\Symantec\Symantec Endpoint Protection Manager\dataApr 08 09, 04:13:58 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win32Apr 08 09, 04:14:00 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win64Apr 08 09, 04:14:11 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win64Apr 08 09, 04:14:59 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win32Apr 08 09, 04:15:07 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win64Apr 08 09, 04:15:28 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM DecomposerApr 08 09, 04:15:38 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win32Apr 08 09, 04:15:41 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win32Apr 08 09, 04:15:44 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win32Apr 08 09, 04:15:54 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win64Apr 08 09, 04:16:02 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win64Apr 08 09, 04:16:18 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win32Apr 08 09, 04:16:19 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win32Apr 08 09, 04:16:36 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Decomposer_lumetadataApr 08 09, 04:16:52 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win64Apr 08 09, 04:16:52 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win32Apr 08 09, 04:16:59 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win64Apr 08 09, 04:17:26 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win64Apr 08 09, 04:17:31 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win32Apr 08 09, 04:17:39 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM AntiVirus Client Win64Apr 08 09, 04:17:50 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win32Apr 08 09, 04:17:59 AM INFO(Med) catalogen SesmLu: Successfully enabled content. SESM Network Access Control Client Win64Apr 08 09, 04:18:08 AM INFO(Med) catalogen SesmLu: PreSession callback... finished. Result: 0Apr 08 09, 04:21:28 AM INFO(Med) catalogen SesmLu: PostSession callback...Apr 08 09, 04:21:28 AM INFO(Low) catalogen SesmLu: PrepareLUDownloads was not run. Skipping PostSession work.Apr 08 09, 04:21:28 AM INFO(Med) SesmContentCatalog: Entered Init().Apr 08 09, 04:21:28 AM INFO(Low) ProductUtil: Data root = C:\Program Files\Symantec\Symantec Endpoint Protection Manager\dataApr 08 09, 04:21:28 AM INFO(Med) sesmAvClient32en SesmLu: PostSession callback...Apr 08 09, 04:21:28 AM INFO(Low) sesmAvClient32en SesmLu: PrepareLUDownloads was not run. Skipping PostSession work.Apr 08 09, 04:21:32 AM INFO(Med) SesmContentCatalog: Entered Init().Apr 08 09, 04:21:32 AM INFO(Low) ProductUtil: Data root = C:\Program Files\Symantec\Symantec Endpoint Protection Manager\dataApr 08 09, 04:21:32 AM INFO(Med) sesmAvClient64en SesmLu: PostSession callback...Apr 08 09, 04:21:32 AM INFO(Low) sesmAvClient64en SesmLu: PrepareLUDownloads was not run. Skipping PostSession work.Apr 08 09, 04:21:35 AM INFO(Med) SesmContentCatalog: Entered Init().Apr 08 09, 04:21:35 AM INFO(Low) ProductUtil: Data root = C:\Program Files\Symantec\Symantec Endpoint Protection Manager\dataApr 08 09, 04:21:36 AM INFO(Med) sesmSnacClient32en SesmLu: PostSession callback...Apr 08 09, 04:21:36 AM INFO(Low) sesmSnacClient32en SesmLu: PrepareLUDownloads was not run. Skipping PostSession work.Apr 08 09, 04:21:36 AM INFO(Med) SesmContentCatalog: Entered Init().Apr 08 09, 04:21:36 AM INFO(Low) ProductUtil: Data root = C:\Program Files\Symantec\Symantec Endpoint Protection Manager\dataApr 08 09, 04:21:37 AM INFO(Med) sesmSnacClient64en SesmLu: PostSession callback...Apr 08 09, 04:21:37 AM INFO(Low) sesmSnacClient64en SesmLu: PrepareLUDownloads was not run. Skipping PostSession work.Apr 08 09, 04:21:46 AM INFO(High) SesmLu: Apr 08 09, 04:21:46 AM INFO(High) SesmLu: ***************************************************************************************************************Apr 08 09, 04:21:46 AM INFO(High) SesmLu: **** Starting New SesmLu Session ****Apr 08 09, 04:21:46 AM INFO(High) SesmLu: **** Platform: Microsoft Windows Server 2003Apr 08 09, 04:21:46 AM INFO(High) SesmLu: **** SesmLu Version: 11.0.4000.2295Apr 08 09, 04:21:46 AM INFO(High) SesmLu: ***************************************************************************************************************Apr 08 09, 04:21:46 AM INFO(Med) SesmLu: PreSession callback...Apr 08 09, 04:21:46 AM INFO(Med) TomcatServerXml: Entered Init().Apr 08 09, 04:21:46 AM INFO(Med) SesmLu: http://127.0.0.1:9090/servlet/ConsoleServlet?Actio... 08 09, 04:21:46 AM INFO(Low) SesmLu: <?xml version="1.0" encoding="UTF-8"?>
<Response ResponseCode="0"/>
Not running...
How may computers are we talking about here? Is it just one computer are a group of computers in a network. And do you use any network load balancing?
“Your most unhappy customers are your greatest source of learning.”
Just the Manager
I have a network of 150 clients that get their signature update from the manager which is supposed to download the LIVE UPDATES. I don't use load balancing.
In case of this issue i will
In case of this issue i will advice you to Upgrade to 11.0.4014.
Regards'
Ajit Jha
Technical Consultant
STS
link from another discussion
maybe this also helps:
https://www-secure.symantec.com/connect/forums/sep...
“Your most unhappy customers are your greatest source of learning.”
I have meet the same situation before
I have meet the same situation before, it because I have set one of the invalid DNS server in TCP/IP settings.
After I fix this DNS server's problem, the error solved.
Please check and try again?
Re
Good point from Rose, please make sure clients and servers are communicating well. Can you see these questioned clients on the SEPM console? Or the SEPM is the one having problems with the updates. Check your internet connectivity.
I found another link that
I found another link that might help...
http://service1.symantec.com/SUPPORT/ent-security....
I just don't know how to use it. I want to be able to use it too if it works.
“Your most unhappy customers are your greatest source of learning.”
Update ur Status
Update ur Status
Regards'
Ajit Jha
Technical Consultant
STS
Do you have any Internet
Do you have any Internet Proxy Server? If so, then configure the live update to use Proxy for getting updates.
you can change your
you can change your liveupdate timeout setting from default to any maximum.
Symantec endpoint is a badproduct, always the same problems...
I have the same problem, I have a proxy but it doesn't work, so I'm going to get a support ticket in symantec and they resolve their bad product.
Hi DannyBoy
Have you seen this article yet. You should look through it, and you might get a solution quicker than if you phone in.
http://service1.symantec.com/SUPPORT/ent-security....
Cheers,
Grant
Please don't forget to mark your thread solved with whatever answer helped you : )
Would you like to reply?
Login or Register to post your comment.