Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Symantec Endpoint Protection Manager v11 client update

Updated: 30 Dec 2010 | 15 comments
aconti's picture
0 0 Votes
Login to vote

Hello,

can you please help out in troubleshooting a particular client machine with windows 7 and just re-installed Windows and deployed Symantec EndPoint Security from the server.

The problem is that this machine is not getting anti virus update definitions and even if I run Update Content on the machine from the server, the status says completed 100% however still virus definitions are not updating.

How can I troubleshoot client to server communication and what issues do normally cause this to happen.

 

Thanks

Comments

Mudit Kumar's picture
30
Dec
2010
0 Votes 0
Login to vote

Check for Windows Firewall on

Check for Windows Firewall on the machine, if it is ON.

Also check the following article

Title: 'Symantec Endpoint Protection: LiveUpdate Troubleshooting Flowchart'
Web URL: http://www.symantec.com/docs/TECH95790

Thanks & Regards,
Mudit Kumar
 

VKalani's picture
30
Dec
2010
0 Votes 0
Login to vote

Does the SEP client yellow

Does the SEP client yellow shield have a green dot on it? Green dot is an indication of communication being fine with the server. If it does not  have green dot, then the client is not communicating.

Is the sepm server itself updated?

 

 

 

 

-VKalani

aconti's picture
30
Dec
2010
0 Votes 0
Login to vote

the SEP client does not show

the SEP client does not show a green dot on its icon on the taskbar.

I will check the link and troubleshoot from there

Windows Firewall is off

Rafeeq's picture
30
Dec
2010
1 Vote +1
Login to vote

hi

run the secars test

http://www.symantec.com/business/support/index?page=content&id=TECH102682&locale=en_US

check the windows firewall on your sepm server and windows 7 machine

replace the sylink file from another working green dot machine.

http://www.symantec.com/business/support/index?page=content&id=TECH102322&locale=en_US

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

VKalani's picture
30
Dec
2010
1 Vote +1
Login to vote

Enable the Sylink.log file.

Enable the Sylink.log file. Wait for about 20 minutes. Then upload the sylink.log  file. That would exactly tell us, why the client is not communicating.

How to enable Sylink Debugging for Symantec Endpoint Protection in the registry 

http://www.symantec.com/business/support/index?page=content&id=TECH104758&actp=search&viewlocale=en_US&searchid=1293724293862 

 

BTW, if you are using  IE 9 beta, please uninstall it.

-VKalani

aconti's picture
30
Dec
2010
0 Votes 0
Login to vote

I just found out that I have

I just found out that I have more than 70% of the pc's with Anti Virus Defintion Update Failures

what I cannot understand is that the clients which are updating have their anti virus definition date nearly all different from eachother even when I checked a couple of machines with same OS.

what could cause such a general anti-virus definition update issue

which of the above tools I should use for SEPM ver 11.0.6100 and does it work on server 2008 or it needs Windows XP/Vista/7

 

thanks

pete_4u2002's picture
30
Dec
2010
1 Vote +1
Login to vote

what I cannot understand is

what I cannot understand is that the clients which are updating have their anti virus definition date nearly all different from eachother even when I checked a couple of machines with same OS.

There could be communication issue with the server or Definition may have corrupted.

 

which of the above tools I should use for SEPM ver 11.0.6100 and does it work on server 2008 or it needs Windows XP/Vista/7

You can enable the sylink logs, which can be used on all kinds of OS machine.

http://www.symantec.com/business/support/index?page=content&id=TECH104758&actp=search&viewlocale=en_US&searchid=1293724293862

 

As well as you can try copying the sylink replcaer on other machines and see if it gets update to rule out the communication issue.

Brian81's picture
30
Dec
2010
0 Votes 0
Login to vote

Try clearing out definitions

Try clearing out definitions on this machine:

How to clear out corrupted definitions for a Symantec Endpoint Protection Client manually

http://www.symantec.com/business/support/index?pag...

aconti's picture
02
Jan
2011
0 Votes 0
Login to vote

Hello,   can I just debug and

Hello,

 

can I just debug and see logs just by doing the below only.

 

SMC debugging can also be enabled and disabled from within the SEP Client by opening the SEP client, then going to: Help and Support -> Troubleshooting... -> Debug logs -> Client Management -> Edit Debug Log Settings.  Then check or uncheck Debug On.

Prachand's picture
02
Jan
2011
0 Votes 0
Login to vote

Yes , that's what is need's

Yes , that's what is need's to be done.

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)

aconti's picture
03
Jan
2011
0 Votes 0
Login to vote

Hello, I have just enabled

Hello,

 

I have just enabled logging by doing this only:

 

SMC debugging can also be enabled and disabled from within the SEP Client by opening the SEP client, then going to: Help and Support -> Troubleshooting... -> Debug logs -> Client Management -> Edit Debug Log Settings.  Then check or uncheck Debug On. 

 

the virus definitions last updated on the 15th of December

 

how do I troubleshoot the log and what do i have to search for to see where is the issue please ?

 

I have also run the secars test http://server:8014/secars?hello,secars and worked fine from the client

And also this:

http://server:8014/reporting/login/login.php

 

pete_4u2002's picture
03
Jan
2011
1 Vote +1
Login to vote

post the logs, contributors

post the logs, contributors can help with the analysis..

Mick2009's picture
03
Jan
2011
0 Votes 0
Login to vote

May Wish to Open a Case

Hi Aconti,

 

Some important questions: Is there more than one SEPM in your organization?  Do all of the out-of-date clients update from the same SEPM?  Are the definitions on that SEPM up to date / are any of its clients up to date?

 

You may also wish to open a case with Symantec Technical Support, rather than relying upon this voluntary peer-support forum.  Keeping AV definitions up-to-date is a serious concern, with the number of new threats that appear every day.  Tech Support can provide timely, expert analysis of the logs in question.

 

Thanks and best regards,

 

Mick

With thanks and best regards,

Mick

aconti's picture
03
Jan
2011
0 Votes 0
Login to vote

hello, one SEPM and all

hello,

one SEPM and all clients connected to it

SEPM seems to be updated as some of the clients and even the one installed on the same SEPM server are up to date

is there any error I can check from the log that I enabled or some other way to troubleshoot

thanks again

pete_4u2002's picture
03
Jan
2011
0 Votes 0
Login to vote

check for the

check for the communication.

sylink log should be helpful along with the sep support tool.