Endpoint Protection

 View Only
Expand all | Collapse all

Client definition date is wrong

IN007

IN007Mar 30, 2017 10:44 AM

  • 1.  Client definition date is wrong

    Posted Mar 30, 2017 09:15 AM

    I have one client that is showing the definition version that hasn't been published by Symantec. Pictures attached.This is the client that is on the same server as SEPM. All are using the same policy settings.

    screenshot.1490879060_0.png

    screenshot.1490879074.png

    screenshot.1490879370.png



  • 2.  RE: Client definition date is wrong

    Broadcom Employee
    Posted Mar 30, 2017 09:19 AM

    it could be rapid release definition that has been updated.



  • 3.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:20 AM

    It must've got it from Symantec LiveUpdate. Did you verify? The System log will show when/where it was downloaded.



  • 4.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:30 AM

    It got them from liveupdate.symantecliveupdate.com

     

    Where can I check to see if it's getting Rapid Release definitions?



  • 5.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:32 AM

    It sounds like your policy is configured to allow clients to go out to Symantec LU as well as get them from the SEPM. IS this what you want and did you check your LU policy? 



  • 6.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:35 AM

    LU policy does allow them to get definitions directly from Symantec. I don't see where to allow/not allow rapid release definitions.



  • 7.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:38 AM

    Rapid release needs to be manually dropped on the SEPM.

    To me this looks like the client went out to LU and it had later content than the SEPM. This isn't abnormal.



  • 8.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:44 AM

    How do I manually drop rapid release from the SEPM?



  • 9.  RE: Client definition date is wrong

    Posted Mar 30, 2017 09:46 AM
    See here: http://www.symantec.com/docs/TECH104979 http://www.symantec.com/docs/TECH102607


  • 10.  RE: Client definition date is wrong

    Posted Mar 30, 2017 10:14 AM

    Both of those articles show how to apply rapid release defintions. I don't see where it says to remove rapid release definitions?



  • 11.  RE: Client definition date is wrong

    Posted Mar 30, 2017 10:21 AM

    There is no removing definitions. How do you know RR were even applied? This is a manual process to apply them. All I'm saying is the client went out to Symantec LU to get an update because your policy allows for it. I guess I'm confused on what the exact issue is here. The incorrect dates are likely just cosmetic and eventually work itself out. Either that or your SEPM hasn't reached out to Symantec LU to update itself. This is nothing new as I've seen this many times.



  • 12.  RE: Client definition date is wrong
    Best Answer

    Posted Mar 30, 2017 10:42 AM
    Hi, Thia is a certified definition, find the file attached Here's what may have happened... Today 03/30/2017, client may have tried reaching SEPM for definitions but it might habe failed for many reasons... So as configured, SEP went to live update server where it found this new certified rev 04 definition and downloaded it... https://www.symantec.com/security_response/definitions/certified/ So the question is why not SEPM has got this revision because it has not yet checked for the definition. SEPM will check that at its scheduled time.


  • 13.  RE: Client definition date is wrong

    Posted Mar 30, 2017 10:44 AM

    Screenshot_2017-03-30-20-07-15-321_com.brave_.browser.png



  • 14.  RE: Client definition date is wrong

    Posted Mar 30, 2017 10:47 AM

    I think our miscommunication came when you said "Rapid release needs to be manually dropped on the SEPM". I took "dropped" as in deleted, I believe you meant it as downloaded/applied.

     

    Makes much more sense to me now. I have changed the policy so that the client will only check the SEPM now so it won't look like clients are ahead of the SEPM.

     

    Thank you for your help!



  • 15.  RE: Client definition date is wrong

    Posted Mar 30, 2017 10:49 AM

    My fault :) Yes, I meant downloaded and applied.

    Sounds good. Check back if you need anything else.