Endpoint Protection

 View Only
  • 1.  SEPM 12.1 is not updating current definition from an internal LUA 2.3 server.

    Posted Nov 27, 2014 04:37 PM

    Dears,

    I am spending lots of hours to find a solution to these problem but so far no luck..

    We have SEPM 12.1 running on one server and an internal LUA 2.3 server is also configured on a different server and LUA is downloading updates perfectly and I was able to distribute definitions. But now the problem is SEPM 12.1 is showing definition 2014004.016 and NOT updating current definition until now.

    I was checking almost all the forum discusions and I am hoping that I would get the solution to these prevailing problem.. 

    These are the links I checked but no luck!

    1. http://www.symantec.com/business/support/index?page=content&id=TECH166923

    2. http://www.symantec.com/connect/articles/how-clear-corrupt-virus-definitions-sepm

    Here's what I am getting when ever I tried to download definition on SEPM 12.1

    Time Stamp,Severity,Event Type,Event Description,Message ID,Error Code,Stack Trace,Server Name,Site Name
    11/27/2014 22:07:33,Info,LiveUpdate manual task succeeded,LiveUpdate succeeded.,,,,Server-Name,Sitename
    11/27/2014 22:07:33,Info,LiveUpdate All process finished,LUALL.EXE finished running.,,,,Server-Name,Sitename
    11/27/2014 22:07:33,Info,LiveUpdate All process finished,LUALL.EXE finished.  There were no new content updates. Return code = 1.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for Symantec Endpoint Protection Win64 12.1 (English).,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for Symantec Endpoint Protection Win32 12.1 (English).,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for Centralized Reputation Settings 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for SONAR scan engine Win32 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for AP Portal List 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for TruScan proactive threat scan commercial application list Win32 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for SONAR scan whitelist Win64 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for Virus and Spyware definitions Win32 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:32,Info,Download is current,No updates found for Intrusion Prevention signatures Win64 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Client Intrusion Detection System signatures 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Revocation Data 12.1 RU2 .,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SONAR scan engine Win64 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Submission Control signatures 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Submission Control signatures 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SONAR scan data 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Symantec Whitelist 12.1 RU2 .,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SONAR Heuristics engine 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SONAR scan whitelist Win32 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Symantec Endpoint Protection Manager Content Catalog 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for TruScan proactive threat scan commercial application list Win64 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SEPM LiveUpdate Database 12.1.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for SONAR scan commercial application engine 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Extended File Attributes and Signatures 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Power Eraser Definitions 12.1 RU5.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Virus and Spyware definitions Win64 12.1 RU2.,,,,Server-Name,Sitename
    11/27/2014 22:07:31,Info,Download is current,No updates found for Intrusion Prevention signatures Win32 11.0.,,,,Server-Name,Sitename
    11/27/2014 22:07:21,Info,LiveUpdate All process launched,LUALL.EXE has been launched.,,,,Server-Name,Sitename
    11/27/2014 22:07:21,Info,LiveUpdate manual task started,Download started.,,,,Server-Name,Sitename

    Also seeing an error

    Error,An unexpected exception has occurred,Failed to read E:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\tomcat\temp\threatcon.zip,Failed to read file.,Failed to read file.,com.sygate.scm.server.util.ServerException: Failed to read E:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\tomcat\temp\threatcon.zip     at com.sygate.scm.server.task.SecurityDataTask.processThreatCon(SecurityDataTask.java:225)     at com.sygate.scm.server.task.SecurityDataTask.execute(SecurityDataTask.java:79)     at com.sygate.scm.server.task.MonitoredTimerTask.run(MonitoredTimerTask.java:22)     at java.util.TimerThread.mainLoop(Timer.java:555)     at java.util.TimerThread.run(Timer.java:505)

     



  • 2.  RE: SEPM 12.1 is not updating current definition from an internal LUA 2.3 server.

    Posted Dec 21, 2014 01:22 PM

    Start troubleshooting by running the symhelp tool on it to check for issues:

    Download the Symantec Help (SymHelp) diagnostic tool to detect Symantec product issues

    Exact version of SEPM that you're running?



  • 3.  RE: SEPM 12.1 is not updating current definition from an internal LUA 2.3 server.

    Posted Dec 22, 2014 05:15 AM
      |   view attached

    As the logs seems to suggest your SEPM is after the below defs, I'm assuming you have a 12.1RU5 install:

    11/27/2014 22:07:31,Info,Download is current,No updates found for Power Eraser Definitions 12.1 RU5

    In which case, can you confirm you have the RU5 content selected for download in your LUA?  Remember that there are different options available depending on the version of SEP you're downloading for (see attached screenie).

    After that, it's just a matter of ensuring your download and distribution jobs are configured for the Manager defs and not the client ones...