Endpoint Protection

 View Only
  • 1.  SEP 11.0.6. - Reports/Alerts on ALL definition files, not just virus?

    Posted Apr 21, 2011 04:10 PM

    I know that SEP allows you to generate reports and alerts based on virus definition file versions, however I have not found a way to generate alerts or reports for clients that have out of date Proactive Threat Protection or Network Threat Protection definitions.

    It seems that I can only view this information by viewing the properties on machines individually.  We are using the embedded database so unfortunately I can't just hop onto a SQL db and cook up my own query.

    Does anyone else know how to do this?  Am I just missing something hidden away in the reporting section?

    The reason this is an issue is because I have discovered machine in our environment that are successfully updating the virus definition files, but one of the other definition files may be weeks or months out of date (and the only dependable fix I've found so far is to do a reinstallation of SEP).  I'd like to be able to easily identify these machines so that they can be fixed.



  • 2.  RE: SEP 11.0.6. - Reports/Alerts on ALL definition files, not just virus?

    Posted Apr 21, 2011 05:43 PM

    Unfortunately at this time there is no way to generate a report like this for those definitions.

    If you are adept at queries you can try connecting to the database using the [SEPM]\ASA\win32\dbisql.exe tool: log in using DB credentials (admin/initial admin password) in Login tab, and in the Database tab, choose sem5.db within the [SEPM]\db folder. (Perhaps backing up database using Database Back Up and Restore before connecting this way would be prudent smiley )

    sandra



  • 3.  RE: SEP 11.0.6. - Reports/Alerts on ALL definition files, not just virus?

    Posted Apr 21, 2011 06:20 PM

    Doh.  I think I'm more likely to grab the information via an Altiris script and pipe it into a custom data class, but I'm glad to at least have a definitive answer!

    Do you know if this is something that will be changed in v. 12?



  • 4.  RE: SEP 11.0.6. - Reports/Alerts on ALL definition files, not just virus?
    Best Answer

    Posted Apr 21, 2011 06:31 PM

    There are reports that may help you:

    Computer status > Intrusion Prevention Signature Distribution report

    Computer status > Protection Content Versions report

    But no possibility to generate a notification for these informations.



  • 5.  RE: SEP 11.0.6. - Reports/Alerts on ALL definition files, not just virus?

    Posted Apr 21, 2011 06:49 PM

    Nice.  A scheduled report will meet our needs at this point, especially since I can schedule those to run periodically.  Thanks a ton!