Endpoint SWAT: Protect the Endpoint Community

 View Only
Expand all | Collapse all

Last status change older than today's date -SEP 11Ru7

  • 1.  Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 03:41 AM

    We have noticed a lot of machines that for some reason is showing up with older date and times on the "last status field" in the console, yet they
    are online(green dot) but contiunously out of date??? Any idea/reason?



  • 2.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 04:15 AM

    check this

    Clients cannot send data back to Symantec Endpoint Protection Manager

    http://www.symantec.com/docs/TECH105348

     
     
    Kindly try this troubleshooting step: 

    1. Browse to \Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\agentinfo

    2. Look for any .err files or tmp files & Dat files

    3. If you find anything which is not processed by sepm then it might be the reason for the client data loss

    4. Stop SEPM services from services.msc 

    5. Delete all the files inside the location \Program Files\Symantec\Symantec Endpoint Protection Manager\data\inbox\agentinfo

    6. Restart the SEPM services.

    Check the SEPM now if still issue persist go for step 7

     

    7. Run the Management server configuration wizard.

    Note: While running Management server configuration wizard it requires Database password. if you running SEP 12.1.2 it wont prompt you for DB password.

     

    Kindly update us the status .... thanks 



  • 3.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 05:02 AM

    Checked and no err , tmp or dat files that have not been processed in the inbox\agent info. What I have done it delete the machine from the console and see what the machine reports back after re-appearing on the console.

    Looking at the outbox\agent - there is one folder I am unable to delete even with the SEPM service stopped?



  • 4.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 05:35 AM

    Try to delete after stop the Symantec Embedded Database and Symantec Endpoint Protection Manager service from services.msc

     


  • 5.  RE: Last status change older than today's date -SEP 11Ru7

    Broadcom Employee
    Posted Mar 05, 2014 05:41 AM
    do not delete the folders.
     
    can you enable sylink log to see if it is sending the information to SEPM?


  • 6.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 05:49 AM

    How many clients having same problem?

    clients have reflect again after delet from console?

    Restart the SEPM Database Service and wait for next communication.



  • 7.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 05, 2014 05:58 AM

    whats that folder name, the problem seems to be at the SEPM end.. what version you are running?



  • 8.  RE: Last status change older than today's date -SEP 11Ru7

    Broadcom Employee
    Posted Mar 05, 2014 10:36 AM

    Hi,

    Thank you for posting in Symantec community.

    What's the SEP version?

    It was a known issue prior to SEP 12.1 RU1 MP1, it has been fixed in 12.1 Release Update 1 Maintenance Pack 1

    Last Time Status Change does not update for some clients
    Fix ID: 2632371
    Symptom: The SEPM console shows clients with an outdated "Last Time Status Changed" timestamp. The clients are online and functioning correctly.
    Solution: A deadlock in SEPM was resolved to allow the agent status to be updated properly
     
    Reference: New fixes and features in Symantec Endpoint Protection 12.1 Release Update 1 Maintenance Pack 1
     


  • 9.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 06, 2014 12:35 AM

    I am running SEP11Ru7MP2. I deleted the clients and waiting to see what they report in as.



  • 10.  RE: Last status change older than today's date -SEP 11Ru7

    Broadcom Employee
    Posted Mar 06, 2014 09:11 AM

    Right, that can be one of the step to troubleshoot this issue.

    Also can repair the SEPM.

    It has happend first time?

    Why don't you upgrade to the latest version of SEPM? Upgrade to the latest available release of SEP to enjoy many other enhancements and improvements. smiley

     



  • 11.  RE: Last status change older than today's date -SEP 11Ru7

    Posted Mar 07, 2014 01:18 AM

    We are running both SEP 11 and SEP 12 environments - both 25000 devices. Migration to SEP12 is not easy as the customer has a complicated network. 

    I think it has happended before, but not sure how far back. Will be upgrading the SEP 11Ru7 to SEP 11ru7mp4 and see then.