Endpoint Protection

 View Only
Expand all | Collapse all

SEPM not updating with Liveupdate

  • 1.  SEPM not updating with Liveupdate

    Posted Jun 17, 2011 06:12 AM

    Everything seems working fine but all SEPM is not updating

    June 17, 2011 3:07:38 PM BDT:  LiveUpdate succeeded.  [Site]  [Server]

    June 17, 2011 3:07:38 PM BDT:  LUALL.EXE finished running.  [Site]  [Server]

    June 17, 2011 3:07:38 PM BDT:  LiveUpdate will start next on Friday, June 17, 2011 5:07:38 PM GMT+06:00 on Server.  [Site]  [Server]

    June 17, 2011 3:07:38 PM BDT:  LUALL.EXE finished.  There were no new content updates. Return code = 1[Site]  [Server]

    June 17, 2011 3:07:30 PM BDT:  Symantec Endpoint Protection Win64 11.0.4202.75 (English) is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:29 PM BDT:  Symantec Endpoint Protection Win64 11.0.5002.333 (English) is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:27 PM BDT:  Symantec Endpoint Protection Win32 11.0.4202.75 (English) is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:25 PM BDT:  Symantec Endpoint Protection Win32 11.0.5002.333 (English) is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:24 PM BDT:  Symantec Endpoint Protection Win32 11.0.6200.754 (English) is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:23 PM BDT:  TruScan proactive threat scan engine Win32 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:23 PM BDT:  TruScan proactive threat scan commercial application list Win32 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:22 PM BDT:  TruScan proactive threat scan whitelist Win64 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:22 PM BDT:  Intrusion Prevention signatures Win64 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:21 PM BDT:  TruScan proactive threat scan engine Win64 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:21 PM BDT:  Submission Control signatures 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:21 PM BDT:  TruScan proactive threat scan data 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:20 PM BDT:  TruScan proactive threat scan whitelist Win32 11.0 is up-to-date.    [[Site]  [Server]

    June 17, 2011 3:07:20 PM BDT:  TruScan proactive threat scan commercial application list Win64 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:19 PM BDT:  Antivirus and antispyware definitions Win32 11.0 MicroDefsB.CurDefs is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:19 PM BDT:  Decomposer Win32 and Win64 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:19 PM BDT:  Symantec Endpoint Protection Manager Content Catalog 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:19 PM BDT:  TruScan proactive threat scan commercial application engine 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:18 PM BDT:  Antivirus and antispyware definitions Win64 11.0 MicroDefsB.CurDefs is up-to-date.    [Site]  [Server]

    June 17, 2011 3:07:18 PM BDT:  Intrusion Prevention signatures Win32 11.0 is up-to-date.    [Site]  [Server]

    June 17, 2011 3:05:38 PM BDT:  LUALL.EXE has been launched.  [Site]  [Server]

    June 17, 2011 3:05:38 PM BDT:  LiveUpdate started.  [Site]  [Server]



  • 2.  RE: SEPM not updating with Liveupdate

    Broadcom Employee
    Posted Jun 17, 2011 06:52 AM

    Hi,

    Could you please attach screen shot of show liveudpate downloads.

    Path is as follow:

    SEPM --> Admin--> Server --> local site --> Show liveupdate downloads



  • 3.  RE: SEPM not updating with Liveupdate

    Posted Jun 17, 2011 07:12 AM


  • 4.  RE: SEPM not updating with Liveupdate

    Posted Jun 17, 2011 08:52 AM

    Try to run a manual liveupdate

    start > run > Luall.exe and see if that helps.



  • 5.  RE: SEPM not updating with Liveupdate

    Posted Jun 17, 2011 09:55 AM

    You can try to increase the number of LiveUpdate revisions your SEPM can hold:

    Admin > Servers > Edit Site Properties > LiveUpdate tab > Disk Space Management for Downloads

     

    You can also check the size of the "Content" filegroup in your SEPM DB.  It has a cap and if this is filled, you will have issues download LiveUpdate content:

    http://www.symantec.com/business/support/index?page=content&id=TECH106075&locale=en_US

     

     



  • 6.  RE: SEPM not updating with Liveupdate

    Posted Jun 17, 2011 10:43 AM

    The lines you copied show SEPM/LiveUpdate does not detect any new updates. Please ensure:

     

     - SEPM is not already updated (follow what Chetan mentioned)

     - catalog is up-to-date (will be visible in the screenshot Chetan mentioned)

     - SEPM is not configured to retrieve definitions from internal out-of-date LiveUpdate Administrator (can be checked in SEPM > Admin > Servers > Local Site > Properties > LiveUpdate > Source servers)

     

    Please copy on this thread content of Log.liveupdate file (located in C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate or c:\ProgramData\Symantec\LiveUpdate).



  • 7.  RE: SEPM not updating with Liveupdate

    Posted Jun 20, 2011 07:41 AM


  • 8.  RE: SEPM not updating with Liveupdate

    Posted Jun 22, 2011 05:42 AM
      |   view attached

    Hi all,

    I have same problem. My SEPM can't update virus definition from Liveupdate server since 18 June 2011. I've tried all solutions that you suggested but still not ok. Only the virus definition updates are not updated. Anyone can explain where is the problem?



  • 9.  RE: SEPM not updating with Liveupdate

    Posted Jun 22, 2011 05:47 AM

    As mentioned in my previous comment, please upload log.liveupdate to that thread.



  • 10.  RE: SEPM not updating with Liveupdate

    Posted Jun 23, 2011 04:08 AM
      |   view attached

    Here is my log.liveupdate. I hope we can solve this problem. Thanks before.

    Attachment(s)

    txt
    log.liveupdate_5.txt   1.11 MB 1 version


  • 11.  RE: SEPM not updating with Liveupdate

    Broadcom Employee
    Posted Jun 23, 2011 05:56 AM

    Hi,

    Uninstall liveupdate, delete the definitions with the help of following article

     
    Reinstall Liveupdate
     
    Re-registered Liveupdate with SEPM using lucatalog -update
     
    Run liveupdate
     
     
     
       


  • 12.  RE: SEPM not updating with Liveupdate

    Posted Jun 23, 2011 06:25 AM

    Your log shows new content is detected and downloaded successfully:

     

    EVENT - PRODUCT UPDATE SUCCEEDED EVENT - Update available for Antivirus and antispyware definitions Win32 11.0 MicroDefsB.CurDefs - MicroDefsB.CurDefs - SymAllLanguages. Update for CurDefs takes product from update 110617020 to 110622038

     

     

     

    EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 10 updates available, of which 10 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 1800, Success

     

    I would suggest you then to upload c:\Program Files\Symantec\Symantec Endpoint Protection Manager\tomcat\logs\sesmlu.log as well. This log will show how SEPM handle LiveUpdate new definitions.

     

     



  • 13.  RE: SEPM not updating with Liveupdate

    Posted Jun 23, 2011 11:25 PM

    Like batotoy said earlier everything seems working fine but actually virus definitions in my SEPM is not update (Network Threat and Proactive Threat definitions already updated). Here I attached the file. Thanks.

    Attachment(s)

    txt
    SesmLu.log_.txt   3.29 MB 1 version


  • 14.  RE: SEPM not updating with Liveupdate

    Posted Jun 28, 2011 01:15 PM

    I am having identical problem.  Stopped updating about the 10th of June.  got it running again, but only runs once after uninstalling, reinstalling, cleaning up and reregistering, then never updates the manager again.  Always the 1814 error and Error Code = 4.  I have been plaqued with this for 3 years at this one customer's site.  I always get it back, but it winds up breaking again eventually.  I just updated the SEPM to 11.0.6300.

    And will not update the clients until the manager updates.



  • 15.  RE: SEPM not updating with Liveupdate

    Posted Jun 29, 2011 09:32 PM

    Try the following:

     

    - Uninstall LiveUpdate
    - reboot server
    - Delete C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate & C:\Program Files\Common Files\Symantec Shared\SymcData folders
    - Resintall LiveUpdate

    Open command prompt: Change directory to the following:-

    C:\Program Files\Symantec\Symantec Endpoint Protection Manager\bin
    (depending on which drive SEPM is installed.)

    Then type: lucatalog -cleanup
    Enter

    Then type: lucatalog -update
    Enter

    Now run a repair on SEPM

    Try the steps for a second time if it does not work on the first time.

    Goodluck !!!



  • 16.  RE: SEPM not updating with Liveupdate

    Posted Jun 29, 2011 09:55 PM

    Hi everyone ,

                     Go to Programfiles/symantec/SEPM/Inetpub/content/ 

    Delete the Folders and then Program Files\Common Files\Symantec Shared\SymcData folders

     

    Go to Task manager check Luall.exe is running , if running stop it and associated processes .

    Go to control panel open the symantec Live update open it .

    General Tab -> Interactive mode -> error support - Enhanched 

    apply and ok Run luall.exe .

    The Liveupdate should run and it will show all the Update .

    If show only Antivirus and antispyware , then Repair SEPM .

    It will fix it .



  • 17.  RE: SEPM not updating with Liveupdate

    Posted Jul 04, 2011 12:02 AM

    I've tried all solutions but still not fixing my problem. Any other idea? Thanks.



  • 18.  RE: SEPM not updating with Liveupdate

    Broadcom Employee
    Posted Jul 04, 2011 05:58 AM

    Hi,

    Go to C:\Program Files\Common Files\Symantec Shared\SymcData\ & rename following folders 
    sesmvirdef32 rename it to sesmvirdef32_1
    sesmvirdef64 rename it to sesmvirdef64_1
     
    In the registry, navigate to follwing keys and rename it just like folders, because folders are mapped with registry
     
    HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\SymcData-sesmvirdef32_1
    HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\SymcData-sesmvirdef6_1
     
    Then go to Start --> Run  & access C:\Program Files\Symantec\Symantec Endpoint Protection Manager\bin (depending on which drive SEPM is installed.)
     
    Then type: lucatalog -cleanup
    Enter
     
    Then type: lucatalog -update
    Enter
     
    Run Liveupdate and check.


  • 19.  RE: SEPM not updating with Liveupdate

    Posted Jul 04, 2011 06:28 PM

    Hi ,

          Try to repair the SEPM and also the Symantec live update from add/remove program .



  • 20.  RE: SEPM not updating with Liveupdate

    Posted Jul 07, 2011 05:22 AM

    Still not working normally. Almost a month I've worked for this and still not get good results. Additional info, I am using Windows Server 2008 Enterprise Edition 32-bit and SEPM 11.0.6200.754.There's no folder called C:\Program Files\Common Files\Symantec Shared\SymcData\ in my server. SymcData folder sits on C:\ProgramData\Symantec\Definitions\SymcData. Is it normal?

    Then, every time I run the LiveUpdate virus definitions in the folder {C60DC234-65F9-4674-94AE-62158EFCA433} is not moving from the date 110617020. But LiveUpdate log said that the LiveUpdate successfully update and no error. It's like virus definitions locked on this date.



  • 21.  RE: SEPM not updating with Liveupdate

    Posted Jul 07, 2011 12:34 PM

    Hi,

     It is normal for 2008 . 

    Do the steps, CHETAN suggested .



  • 22.  RE: SEPM not updating with Liveupdate

    Broadcom Employee
    Posted Jul 12, 2011 05:53 AM

    Hi One World,

    I belive either your definitions or catalog corrupted.

    This issue is commonly seen reported with Support calls.



  • 23.  RE: SEPM not updating with Liveupdate

    Posted Jul 12, 2011 06:22 AM

    I don't know the problem but I try to decrease 'Number of content revision to keep' from 100 to 50. Then run 'lucatalog -cleanup' , 'lucatalog -update' and manually LiveUpdate. After that everything seems like OK. Anybody can explain why this can happen?