Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEP 12.1... Clients not appearing in SEPM 12.1 console

Updated: 31 Oct 2011 | 28 comments
InfoSecGuy006's picture
0 0 Votes
Login to vote

I've got a small test group of 10 clients that I've upgraded from various SEP 11 versions to SEP 12.1.671.4971.  Of the 8 of the 10 client are showing up in the SEPM. The 2 clients that don't appear have green dots indicating that they are communicating to the SEPM.  They also have the correct policy. I've verified their communication settings (sylink.xml) file is correct and pointing to the SEPM 12 test server and clients have the latest definitions.

What gives?

Comments

InfoSecGuy006's picture
12
Jul
2011
0 Votes 0
Login to vote

Correction...

Of the 10.. only 8 are showing in the console

Syed Badi ul Hassan's picture
07
Sep
2011
0 Votes 0
Login to vote

Run Rx4DefsSEP tool

Run Rx4DefsSEP tool on the two endpoints that are not visible on the SEPM console. Hope it will resolve the issue.

Rafeeq's picture
12
Jul
2011
0 Votes 0
Login to vote

hi

installed from Image ; check these two documents

 

Symantec Endpoint Protection 11.x client migrated to Endpoint Protection 12.1 does not communicate with new Manager

 

http://www.symantec.com/business/support/index?page=content&id=TECH160977&actp=search&viewlocale=en_US&searchid=1310489675659

 

http://www.symantec.com/business/support/index?page=content&id=TECH162756&actp=search&viewlocale=en_US&searchid=1310489675659

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Chetan Savade's picture
12
Jul
2011
2 Votes +2
Login to vote

Hi,   Possible Cause:The user

Hi,

Possible Cause:The user account used to install SEP existed already in SEM_Client table as a user mode record for some reason.  

Possible Solution
1. Remove all entries in user mode from DB if user mode is NOT intended in environment at all.
delete from sem_client where policy_mode = 0
or
2. Use a switch tool to switch all user mode clients to computer mode. 
or
3. Use a new user account that never used for SEP installation. 
 
The entire process of choosing which group a client belongs to occurs during client registration
 
1) Client forwards SEPM Domain ID, Computer Name, Computer Domain Name, User Name, User Domain Name, Hardware Key, Preferred Mode, and Preferred Group SEPM.

2) SEPM then queries SEM_CLIENT table for any non-deleted Computer Mode record (policy_mode = 1) that matches the SEPM Domain and Hardware Key that were forwarded by the client. If a match is found, it means the client has already been registered with the SEPM in Computer Mode. The group id of the client entry is then returned to the SEP client. If no match is found, go to step 3.

3) SEPM queries SEM_CLIENT table for non-deleted Computer Mode records that match the SEPM Domain, Computer Name and Computer Domain that also have no defined Hardware Key. If a match is found, it means that the SEPM client entry was either imported from AD or was created by clicking Add Computer Account in the SEPM console. The group id associated with this client entry is returned to the SEP client. If no match is found, go to step 4.

4) SEPM queries SEM_CLIENT table for non-deleted User Mode records (policy_mode = 0) that match SEPM Domain, Hardware Key, User Name and User Domain that were forwarded by the client. If a match is found, it means the client has already been registered with the SEPM in User Mode. The group id of the client entry is then returned to the SEP client. If no match is found, go to step 5

5) SEPM queries SEM_CLIENT table for non-deleted User Mode records that match SEPM Domain, User Name and User Domain and no defined Hardware Key. If a match is found, it means the SEPM client entry was either imported from AD or was created by clicking Add User Account in the SEPM console or the user logged on to another computer before. The group id associated with this client entry is returned to the SEP client.
 

Thanks and Regards, 

Chetan Savade

Technical Support Analyst,

End Point Security, Enterprise Technical Support

thedominion's picture
13
Jul
2011
0 Votes 0
Login to vote

I have the same issue in my environment!

None of the resolutions apply!!!

We now have clients that show all information correctly in the client but are not showing in the management console.

Hear4U's picture
14
Jul
2011
0 Votes 0
Login to vote

Check this one out...

Not exactly the same issue, but may spark an idea for you...

https://www-secure.symantec.com/connect/forums/sep...

Subscribe to the upcoming Security Newsletter - Log in, visit your profile, and click on "Newsletter Subscriptions!"

GeoGeo's picture
15
Jul
2011
0 Votes 0
Login to vote

Backup

On this test environment do you have a secondary or replication partner they can speak to if they can't contact the SEPM?

Review my idea for GUP reporting please vote with a yes if you think it's a good idea.

https://www-secure.symantec.com/connect/ideas/gup-report-program

SMLatCST's picture
18
Jul
2011
0 Votes 0
Login to vote

Next Steps

If the sylink file is all correct and you get an 'OK' message when going to "http://SEPM:port/secars/secars.dll?hello,secars" from the client, then you might have to start doing some sylink monitoring (http://www.symantec.com/docs/TECH104758).

Something I noticed recently preventing one of our SEP Clients from communicating with the SEPM (prior to the SEP Client Upgrade however) was proxy settings on the system account, this was resolved using the steps in this article http://www.symantec.com/docs/TECH104926

Without knowing how your LiveUpdate policy is configured, I couldn't say if the fact that the definitions are up-to-date is a red herring or not.

Joel Bowden's picture
18
Jul
2011
1 Vote -1
Login to vote

I have seen this before also,

I have seen this before also, pushing to a client and expecting to see it in the group I selected only to find it in the "Default" group.  Have you checked all groups to make sure it did not stray to the wrong one?

Hear4U's picture
28
Jul
2011
0 Votes 0
Login to vote

See link below, as there are many asking similar questions

Hi,

I'd like to suggest searching the forums and reviewing other content/threads others have created already, which appear to discuss the same issues.  Also, check the "featured threads" at the top of the page (highlighted in yellow) which appear to be issues other's are having over and over, and hence want to consolidate the discussions so everyone can share their respective knowledge and possible solutions.

https://www-secure.symantec.com/connect/forums/sep...

 

Best,

Eric

Subscribe to the upcoming Security Newsletter - Log in, visit your profile, and click on "Newsletter Subscriptions!"

Swapnil's picture
04
Aug
2011
0 Votes 0
Login to vote

Hi Just would like to know do

Hi Just would like to know do you see over deployed status on Sep manager for licensing status ?

Swapnil

SOC Team .

Please don't forget to mark your thread solved with whatever answer helped you.

Joel Bowden's picture
04
Aug
2011
0 Votes 0
Login to vote

License Over deployed

In SEP 12.1 License Management has been added, and it gives the ability to see how many license are in use and yes if you have over deployed.

Gerald Selvaraj David's picture
10
Aug
2011
0 Votes 0
Login to vote

Hi

Yes  might need to check the license bec in SEP 11 you just need a serial number to download the software but in SEP 12 you need license for everything

Yahya's picture
11
Aug
2011
0 Votes 0
Login to vote

Reinstall

Try reinstall:

- uninstall

- restart

- remove the main directory

- install.

 

HWGUID my causing this and fixed with reinstall and deleting

Hans-05's picture
12
Aug
2011
0 Votes 0
Login to vote

Try this...

Hi, not sure if this was mentioned but I'm sure I've read through everything...bt the solution might be a simple one.

The fact that Sylink.xml points to the server does not mean it is communicating. Also the fact that the client has the latest definitions doesn't mean it is updating from the SEPM.

Double check that the client is online by clicking HELP in the SEP client - TROUBLESHOOTING and see what is says next to SERVER under General Information.

If it gives you the server name or IP it is communicating to the SEPM and we have a problem because it is not showig.

If however it shows OFFLINE, it means it is not communicating to the server thus it won't appear in the SEPM untill it at least checks in once.

If that later is the case check that the machines has connection to the server. SECARS as explained in a previous comment is a good test or otherwise run the support tool that can be found on the below link:

http://www.symantec.com/business/support/index?page=content&id=TECH105414

This will give you a full assessment of the client, what's working and what's not.

hope this helps!

Cheers

Bijay.Swain's picture
28
Aug
2011
0 Votes 0
Login to vote

In the sepm console use

In the sepm console use computer mode not user mode. if still that client doen't appear then replace the sylink file on th eclient and reboot

 

kavin's picture
30
Aug
2011
0 Votes 0
Login to vote

u will need to make sure the

u will need to make sure the Management server list has the correct IP address specfied and then replace the sylink file, it should help.

Please check this document for that

http://www.symantec.com/business/support/index?page=content&id=TECH157585

Ajit Jha's picture
01
Sep
2011
0 Votes 0
Login to vote

Guys!!!   Can we have the

Guys!!!

 

Can we have the Screen Shot of the SEPM Client Tab and the Client's Troubleshooting Detail's????

Regards'

Ajit Jha

Technical Consultant

STS

Gerald Selvaraj David's picture
05
Oct
2011
0 Votes 0
Login to vote

Hi

I suspect that it should be Image problem

So did u try to delete all the hardware Id and the again deploy to the same  machine

Thanks

Gerald

Gai-jin's picture
07
Oct
2011
0 Votes 0
Login to vote

I also have computers that

I also have computers that have SEP installed, up to date, and connected to the server, but do not show up in the client list in SEPM.  I've looked through the groups manually, as well as searched for the client by name and ip, and it's not there.

In the past, I've had issues fairly often where some computers don't show up in SEPM, but if you go back and refresh the list a little later, those computers will show up.  Others may have disappeared in the interim.  They're all connected according to the clients, but something causes them not to appear in the console.  As far as I can tell, that's not what's happening this time though, I have one specific computer I've been watching for days, and it has never shown up in the client list in sepm console.

 

edit: LOL -- Of course, just after I posted this, and added screenshots, I went back into the sepm clients screen to look for something, and there was the missing client, listed right where it should be.  No idea why it suddenly appeared after not being listed for a week or more, but it's there now.

Neeraj@fspl's picture
17
Oct
2011
0 Votes 0
Login to vote

SEP client not showing in the SEPM console

Hi,

I hope, you have search in user mode as well. If yes and problem is still the same then you can tried by changing the hardware ID from the SEP client.

Please go through the below instruction:-

1- Delete %programfiles%\Common Files\Symantec Shared\HWID\sephwid.xml.

2-Open the registry and navigate to HKLM\Software\Symantec\Symantec Endpoint Protection\SMC\Sylink\Sylnk.

3-Edit the "HardwareID" value data to be blank.

4-Restart the Symantec Management Client (SMC) service in the services snap-in.

all the above activity need to perform on client machine.

Hope this could help you.

Regards

Neeraj

.KAT.'s picture
26
Oct
2011
1 Vote +1
Login to vote

Try to export a new

Try to export a new communication settings and rename it as Sylink.xml, then do manual replace of sylink. Or you can try to update policy on the client. 

Viraj Shindgikar's picture
26
Oct
2011
0 Votes 0
Login to vote

to resolve the issue

System not reflecting in SEPM Console

 

1.            Open Run and type the command “smc –stop”

2.            Open the service snap-in and stop all “Symantec” related services.

3.            Delete sephwid.xml  file from %programfiles%\Common Files\Symantec Shared\HWID\.

4.            Open the registry and navigate to HKLM\Software\Symantec\Symantec Endpoint Protection\SMC\Sylink\Sylnk .

5.            Edit the "HardwareID" value data to be blank.

6.            Now type the command “smc –start” in the Run Dialogue box.

7.            Start all the “Symantec” related services from Service snap-in.

8.            Restart the system and logon again.

9.            Update the policies on the SEP Client.

1.Delete the “ProxyServer” Value from HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings

2.Delete the values from HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

3.Delete the values from HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

4.Stop and Start smc service

10.          Now check on the SEPM Server if it is registered.

Gurupreet's picture
04
Dec
2011
0 Votes 0
Login to vote

try the following steps :- on

try the following steps :-

on the client machine which is not reporting to SEPM :-

1] stop tamper protection

2] stop smc.exe

3] delete hdid.xml

start smc.exe service

 

Please update the status

Cheers !!

 

SameerU's picture
05
Dec
2011
0 Votes 0
Login to vote

Hi

Please check the firewall is on or OFF

Gerald Selvaraj David's picture
20
Mar
2012
0 Votes 0
Login to vote

Update

Any Update for the  Issue Did  u try the latest version 12.1 RU1

Lawson Poling's picture
27
Mar
2012
0 Votes 0
Login to vote

I'm seeing clients which have

I'm seeing clients which have been imaged and have the same Hardware ID, but they're all showing up in the SEP console. We're running version 12.1.6. I'm wondering if something changed that allows clients with the same Hardware ID to show up in the console, unlike how it was in ver. 11 when they didn't.

Gerald Selvaraj David's picture
03
Apr
2012
0 Votes 0
Login to vote

Hi

Did u Delete the Hardware ID from the image and test it  before deployment ,because when it is deployed to each client a new Hardware ID should be create and will showup with different ID's in the SEPM