Sylink logging or Sylink Monitoring to determine if GUP is sending AV defs to clients
Created: 29 Jan 2013 | Updated: 04 Feb 2013 | 10 comments
This issue has been solved. See solution.
Can you refresh my memory?
I am trying to set up logging on our GUP (SEP 11 RU7 MP1) to determine whether it is communicating with SEP client so it will receive AV definition from GUP rather than SEPM.
Thanks!!!
Discussion Filed Under:
Comments 10 Comments • Jump to latest comment
If enabling the debug on GUP - you should see the defs requests from SEP clients received by GUP:
http://www.symantec.com/business/support/index?pag...
([HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC]
"smc_debuglog_on"=dword:00000001) with output file - debug.log
...this will show you as well all clients connecting to GUP and overview over what is being requested.
Sylink (http://www.symantec.com/business/support/index?pag...) is best to see it from the other side - from SEP client requesting updates from GUP.
You mean these articles?
http://www.symantec.com/docs/TECH97190
http://www.symantec.com/docs/TECH188574
http://www.cstl.com/
Turn on sylink debugging
How to enable Sylink debugging for the Symantec Endpoint Protection 11.x and 12.1 client in the Windows Registry
SEP Knowledge Base
Endpoint SWAT
SebastianZ, One important thing I forgot to add is that we have no access to the 200+ clients in our environment. We can only access SEPM and the 1500 GUPs
Marriage Made in Heaven
If God is for us, who can be against us? --- Romans 8:31
You can enable on the GUPs or use a tool like Wireshark to watch the traffic.
SEP Knowledge Base
Endpoint SWAT
debug log on GUP will help to know if the definition sent to client.
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
Ahhhhhh Brian, I am beginning to appreciate wireshark as well :-)
Marriage Made in Heaven
If God is for us, who can be against us? --- Romans 8:31
Best FREE! tool out there for watching traffic
SEP Knowledge Base
Endpoint SWAT
RSASKA, have you considered those:
https://www-secure.symantec.com/connect/articles/h...
https://www-secure.symantec.com/connect/videos/sep...
...may give you some more visibility over the GUPs as you have quite many of them:D
Sebastian had the solution, although wireshark is very very powerful also!!!
Marriage Made in Heaven
If God is for us, who can be against us? --- Romans 8:31
Would you like to reply?
Login or Register to post your comment.