Security status - attention needed

This issue has been solved. See solution.
Conestoga Rovers's picture

Hi,
I run SEP MR4 MP2 on Windows 2003 SP2 servers and Win XP clients.
On my SEP console the Security status shows Attention needed but when looking for details I see in the log workstation with older virus definition or workstation who did not run a full scan in the last 30 days but all these workstations are not longer running SEP. They are not in my console anymore and I don't know how I can purge these false reports.
Any help is appreciated.
Thanks a lot.

shp's picture

By default SEPM Keeps the

By default SEPM Keeps the client information for 30 days..... Because of that you wil find client which you have already removed from network...
After 30 days SEPM removes the client information (It marks the del flag in the database to "1")
.
Try to reduce this value (It’s available in properties of local site) and your old computers which are not present will go. Then status will be good.

Regards,
Srinivas H.P.
HCL Infosystems Ltd

Prachand's picture

Log into the SEPM and click

Solution

Log into the SEPM and click on the Admin tab.

Click on Servers.

Select the "Local Site" from the list of Servers.

Under "Tasks," select Edit Site Properties.

Under the "General" tab, there is a check box that says "Delete clients that have not connected for X days." By default this is set to 30. Change the number of days as desired.

Click OK.

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Conestoga Rovers's picture

solution worked

After the long weekend my old log cleared and the status is Good.
Thanks a lot!

Conestoga Rovers's picture

Thanks Prachand. I enabled

Thanks Prachand.
I enabled that box, I refreshed my SEP Manager Home page but nothing changed yet in the Security status. Same Attention needed and the same number of in-existing workstations in the reports.
There is a log somewhere that did not purge.
I also logged off and back in to my SEP Manager.

Prachand's picture

Open the IE on the machine

Open the IE on the machine where SEPM is installed type

https://localhost:8443/servlet/ConsoleServlet?Acti...

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

RickJDS's picture

Curious to see if Prachand's

Curious to see if Prachand's url works for you as it didn't work for me.  I have clients in the "more details" screen with failures for more than 30 days ago (logs are set to 30 days).  I had this problem for a LONG time (MR2?).

Jeremy Dundon's picture

The URL needs to be run twice

The first time it is run it flags logs to be deleted.

The second time it actually removes them.

It may not work at all on MR2, I havent tested it on earlier than MR3.

RickJDS's picture

Ran it four times in a row on

Ran it four times in a row on my SEPM MR4 MP2 and I still have many scan, AV and IPS definition failures including quite a few that have no date.  Many have dates older than 30 days.

DougAuto's picture

This is a known "issue" - slated for fix in RU5

Hi -

I had a very similar issue.   I was seeing machines listed in the Security Status report under Scan Failures (never been scanned),  but if you looked at the client itself, or even in the scan log from SEPM,  it was clearly being scanned on our weekly schedule.    I saw a similar issue with some machines related to AV definitions being out of date.    They were flagged in the Security Status "Attention Needed" report, but if you checked the client (or the SEPM logs), you would see they had the correct defs.

This is due to duplicate entries in the database.   Symantec provided me a tool that removed duplicate entries from my database.   If found / deleted 385 entries, and after that my report was clean.

  NOTE:  I am running MR4 MP2 on the SEPMs.  This problem did not affect all my clients.   Just a very small number of them.

Symantec has confirmed to me that this is a known issue slated to be fixed in RU5.

I am keeping my fingers crossed for the real fix in RU5 (which is due in the next few weeks).

Doug 

RickJDS's picture

Doug, was this fixed for

Doug, was this fixed for you?  I just upgraded all SEPM's to RU5 and I still have this problem.  I might have to wait until the logs get swept (I think that happens every night - anyone know for sure?).