Endpoint Protection

 View Only
Expand all | Collapse all

Clients not updating definitions

Migration User

Migration UserOct 29, 2014 11:39 PM

Migration User

Migration UserOct 29, 2014 11:45 PM

Migration User

Migration UserOct 30, 2014 02:35 AMBest Answer

  • 1.  Clients not updating definitions

    Posted Oct 29, 2014 12:16 AM

    Hi,

    I have about 40 plusclients with one SEPM, some of them manage to update to the latest virus def. just fine but some are not updating eventhough I can see them in the clients list and even the policy changes are being applied (so that this proves that there is communication) also I triggered a scan and that also is working, I came to this conclusion by looking at the command status. Also in the same command status it is showing 100% completed when I say send new def. but in fact when I check on the server it is not true. What can I do ?

    My landscape is as follows

    All are Windows Server 2003 servers and clients/users on Windows XP

    SPEM on Windows Server 2003

    Some windows xp and some windows server 2003 clients are not updating.

    How to check what is the problem?

     

    BTW I do update virus def thru .jdb files 



  • 2.  RE: Clients not updating definitions

    Posted Oct 29, 2014 12:21 AM

    first thing to check is to see if clients are  communicating with the sepm?

    do you see green dot on them?

    Is your SEPM updated with JDB? you  can check that under server- show liveupdate downloads and make sure that its updated with 32 and also 64 bit AV/AS defs

     

    enable sylink loggin on one affected  client and post the logs

    http://www.symantec.com/business/support/index?page=content&id=TECH104758

    BTW whats the version  ?

     



  • 3.  RE: Clients not updating definitions

    Posted Oct 29, 2014 12:25 AM

    Does proper Disk space available ?

    Run the symhelp to check any problem are received.

    http://www.symantec.com/docs/TECH170752

    Troubleshooting Client Communication with SEPM

    Article:TECH95789  | Created: 2009-01-26  | Updated: 2012-01-03  | Article URL http://www.symantec.com/docs/TECH95789

    Troubleshooting Out-of-date Definitions on Clients (Part 1)

    http://www.symantec.com/tv/allvideos/details.jsp?vid=2236084589001

    Troubleshooting Out-of-date Definitions on Clients (Part 2)

    http://www.symantec.com/tv/allvideos/details.jsp?vid=2236084558001



  • 4.  RE: Clients not updating definitions

    Posted Oct 29, 2014 01:07 AM

    Run the symhelp tool to find the reason of the defintion not be update.

    Download the Symantec Help (SymHelp) diagnostic tool to detect Symantec product issues

    Article:TECH170752  | Created: 2011-09-29  | Updated: 2014-10-01  | Article URL http://www.symantec.com/docs/TECH170752


  • 5.  RE: Clients not updating definitions

    Posted Oct 29, 2014 01:55 AM
      |   view attached

    Here is the logfile

    and my version is SEP 11.0.xx

    also yes my SEPM server and some other servers and clients are updated to the .jdb file that I put in the SEPM folder.

    Attached is the logfile

    Attachment(s)

    txt
    Sylink_14.txt   210 KB 1 version


  • 6.  RE: Clients not updating definitions

    Posted Oct 29, 2014 02:03 AM

    As of your logs you can try it

    10/29 13:13:05 [7432] AH: (InetWaiting) time out. Timeout period: 320000
    10/29 13:13:05 [7432] Throw Internet Exception, Error Code=4294967287;Internet Session Timeout
    10/29 13:13:05 [7432] <MaintainPushConnection:>COMPLETED
     

    SEP client is not able to communicate with SEPM

    Article:TECH139251  | Created: 2010-09-06  | Updated: 2011-08-15  | Article URL http://www.symantec.com/docs/TECH139251


  • 7.  RE: Clients not updating definitions

    Posted Oct 29, 2014 02:13 AM

    Hello Jack,

    are your clients running IE 9 beta, you need your clients to MP1 to fix the issue

    Managed Symantec Endpoint Protection clients no longer receive updates after Internet Explorer 9 install

    http://www.symantec.com/business/support/index?page=content&id=TECH141506



  • 8.  RE: Clients not updating definitions

    Posted Oct 29, 2014 04:41 AM

    Nope, nobody is running IE9. We are on IE6 (which is very old)



  • 9.  RE: Clients not updating definitions

    Posted Oct 29, 2014 04:43 AM

    This didnot help me much as there is no inactive connection and also SEPM is able to get the policy changes and able to get commands as to scan the computer and such.



  • 10.  RE: Clients not updating definitions

    Posted Oct 29, 2014 04:46 AM

    How many system having problem ?

    does any GUP client available between sep and sepm ?



  • 11.  RE: Clients not updating definitions

    Posted Oct 29, 2014 05:16 AM

    No there is no GUP in between, this is the same as all other clients

    About 10plus clients having this issue.



  • 12.  RE: Clients not updating definitions

    Posted Oct 29, 2014 05:22 AM

    How much disk space available that system ?

    Run the symhelp to check any problem are received.

    http://www.symantec.com/docs/TECH170752

     

    have you try manually update client ?

    How to manually update definitions for a managed Symantec Endpoint Protection Client using the .jdb file

    Article:TECH104363 | Created: 2008-01-07 | Updated: 2014-09-09 | Article URL http://www.symantec.com/docs/TECH104363


  • 13.  RE: Clients not updating definitions

    Posted Oct 29, 2014 05:23 AM

    whats the current defs on these machines? seems like they have very old definitions, when they are trying to download big chunk its getting timed out.

    <File Checksum="1C58EF1C2C3C136FDC132995F5DAB125" DeltaFlag="1" FullSize="502246181" LastModifiedTime="1414486322792" Moniker="{1CD85198-26C6-4bac-8C72-5D34B025DE35}" Seq="141027017"/>



  • 14.  RE: Clients not updating definitions

    Posted Oct 29, 2014 05:44 AM

    I got the symhelp but it is in some proprieatary format. Should I attach it here?



  • 15.  RE: Clients not updating definitions

    Posted Oct 29, 2014 05:46 AM

    Do you have received any error ?

    Try to update first manuaaly and check again it's update automatic or not ?

    20141028-016-v5i32.exe

    http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=sep



  • 16.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:09 AM

    yes, they are from May 2014.

    And now trying to update to the latest ones.

    Timeout? cause that shouldn't be a problem. As the other servers were having the same old def and they managed to update fine.



  • 17.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:27 AM

    can be tricky sometimes, because SEPM can update clients ,delta or full based on what it has. if client requests more than that it wont be able to update, 

    how many revisions you have set in SEPM? default is 30 rev, meaning 10 days def ( approx)

    run this intelligent updater on one machine

    http://www.symantec.com/business/support/index?page=content&id=TECH102391

    wait till tomorrow it should be able to get deltas from SEPM.

    How to change the number of downloaded content revisions that are retained by the Symantec Endpoint Protection Manager versions 11.0. or 12.1

    http://www.symantec.com/business/support/index?page=content&id=TECH104845



  • 18.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:32 AM

    tried this it says installation failed and see the log in users tmp folder.. where is the tmp folder in Windows Server 2003, I looked high and low but couldn't find the log file.



  • 19.  RE: Clients not updating definitions
    Best Answer

    Posted Oct 29, 2014 06:37 AM

    Have you try to reinstall sep client ? How much disk space available ?

    does manually update failed ?



  • 20.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:40 AM

    i32 is for 32 bit client, make sure you have downloaded the appropriate architecture one? Is the OS 32 or 64?

    check again

    http://www.symantec.com/security_response/definitions.jsp



  • 21.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:41 AM

    http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=sep

    You should download 32 / 64 based on your OS arch



  • 22.  RE: Clients not updating definitions

    Posted Oct 29, 2014 06:43 AM

    As of my suggestion you can clean the SEPM server virus defintion.

    Symantec Endpoint Protection Manager 11.x is not updating 32 or 64 bit virus definitions.

    Article:TECH104721  | Created: 2008-01-15  | Updated: 2013-05-17  | Article URL http://www.symantec.com/docs/TECH104721


  • 23.  RE: Clients not updating definitions

    Posted Oct 29, 2014 11:38 PM

    Hi,

    I have about 1GB plus of diskspace.

    Yes manual update using intelligent updater fails and ask me to look at the log file which I am unable to find.



  • 24.  RE: Clients not updating definitions

    Posted Oct 29, 2014 11:39 PM

    Yes it is 32bit. I have checked it .



  • 25.  RE: Clients not updating definitions

    Posted Oct 29, 2014 11:41 PM

    I suggest you can clear some more disk space.

    it's 32 bit or 64 bit OS ?

    Clear corrupted definations and check again.

    How to clear out corrupted definitions for a Symantec Endpoint Protection client manually

    Article:TECH103176  | Created: 2007-01-31  | Updated: 2012-03-29  | Article URL http://www.symantec.com/docs/TECH103176


  • 26.  RE: Clients not updating definitions

    Posted Oct 29, 2014 11:45 PM

    Its 32bit



  • 27.  RE: Clients not updating definitions

    Posted Oct 30, 2014 12:09 AM

    ok I have deleted them, what would u want me to do now?



  • 28.  RE: Clients not updating definitions

    Posted Oct 30, 2014 12:12 AM

    You can clear old defination as per below articles and again manually update defination.

    How to clear out corrupted definitions for a Symantec Endpoint Protection client manually

    How to clear out corrupted definitions for a Symantec Endpoint Protection client manually

    Article:TECH103176  | Created: 2007-01-31  | Updated: 2012-03-29  | Article URL http://www.symantec.com/docs


  • 29.  RE: Clients not updating definitions

    Posted Oct 30, 2014 12:23 AM

    I'm hoping that this should fix.  Uninstall / reinstall the liveupdate component

    http://www.symantec.com/business/support/index?page=content&id=tech102609



  • 30.  RE: Clients not updating definitions
    Best Answer

    Posted Oct 30, 2014 02:35 AM

    Ok Finally resolved it by reinstalling the client.