Scheduled scans & SEPM reporting
Have a client who for the past 6 months has not been using any sort of administrative scheduled scans because of the enourmous performance impact it was having on users being able to effectively use their desktops. I recently enabled these administrative scans again coupled with a WOL job so that it is all done in the wee hours of the morning. Around 80% of all SEP clients ran the scan as scheduled, which considering there is a significant portion of users that have laptops and I only applied this scan to those clients connected to the corporate network is a decent result I think (it even picked up a trojan that the active scanner had missed).
I do have a few questions though;
1) When configuring the scheduled scan I ensured I unticked the retry checkbox in the missed scheduled scan section. I did this because under no circumstances did I want full scans being done during business hours, however dispite this there are a handful of SEP clients that did not kick off their scan until around 9am which is 7 hours after their scheduled start time. Why is this and how can I ensure that if SEP clients don't kick off the scan at anything other than the scheduled time?
2) When in the SEPM console in the clients tab, the sorting seems to be incorrect. When I view a group with the protection technology view and then sort on the last scan time, it appears to sort on day, then month then by year rather by sorting by the date as a whole. For isntance I have the last scan time sorted in ascending order and the last scheduled scan for most clients was on 17/03/10, however I have dates such as 17/11/09 & 21/01/10 further down the list than the scans performed this morning.
3) Again, when in the SEPM console in the same section and view as described above, the last scan time appears to be from when the scan commenced. When I run a report though from the reporting tab the last scan time appears to be from when the scan completed. Why would this last scan time be reported inconsistently across the management console?
Thanks
Comments
hi
what is the version of your SEPM ? the answers to your questions are here, if you are running older version
Administrator scheduled scans are not running at specified times
Fix ID: 1594128Symptom: With missed events disabled, scheduled scans are not correctly flagged as missed events.Solution: Enhanced missed event detection to account for the user environment when detecting missed events
Release notes for Symantec Endpoint Protection 11.0.x and Symantec Network Access Control 11.0.x
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121216360648
.
when scans dont run at specifiied times all the data is reporting is messed up...
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Hi Rafeeq, thanks for the
Hi Rafeeq, thanks for the reply. We're using MR4 MP4, so it looks like an upgrade will be in order. Thanks very much for that.
Anyone have any idea on why there are inconsitencies with the reporting, or sorting by date?
Hi Rafeeq, With his current
Hi Rafeeq,
With his current version, would there be a work around?
I too have been having issues with scheduled scan eating too much performance on my servers.
The next upgrade for me is still for approval.
A quick fix for this would be very appreciated.
thanks.
Nel Ramos
Would you like to reply?
Login or Register to post your comment.