Endpoint Encryption

 View Only
  • 1.  Removing a PC from the Management Console

    Posted Mar 30, 2011 04:52 AM

    We have had to uninstall SEE from some desktops, but in the management console they are still showing as installed.  The checkin date has not moved on so I know the software has been uninstalled, but the management server still shows that FW, FD and RS are installed.  How do you remove the PCs from the console?



  • 2.  RE: Removing a PC from the Management Console

    Posted Apr 04, 2011 09:48 AM

    Is the ADSynch service running ?, if not then start the ADSync and monitor it after few hours.



  • 3.  RE: Removing a PC from the Management Console

    Posted Apr 06, 2011 06:00 AM

    Yes it is running.

    It does ony seem to update the Last Update time weekly, but is does update.

    I have also tried stopping and starting it.



  • 4.  RE: Removing a PC from the Management Console

    Posted Apr 07, 2011 05:30 PM

    I have this same issue--computers that had the software uninstalled still show up in the console.  The only way I was able to get them removed was to remove the computer from the domain then add it back again.  GEHD/SEE seems to keep track of the GUID of the computer object and doing this will create a new GUID.  On the next synch, it should remove the old object and create a new blank one in the console. 



  • 5.  RE: Removing a PC from the Management Console

    Posted Apr 08, 2011 09:46 AM

    In general, changes made to a computer in AD should not create duplicate records in our repository. So if you remove a client from the AD, then it should remove it from the Manger too.
    If you move a different group in the AD, it will not remove it from the OU in SEE Manager.

    The endpoint client is uniquely identified in the database. Computers table by its GEGuid, a GUID generated by the Framework client during its installation.
    (The Computers table contains all the endpoints under management. The ADComputers and NovellComputers tables can contain imported computer objects
    that do not have the Framework installed and have not reported a GEGuid, and are therefore not reflected in the Computers table.)

    There is always only one record in the Computers table for an endpoint, unless the Framework client was un-installed and re-installed (not updated).
    Changing the membership of an endpoint in AD and/or Novell results in modification to the relevant fields in the computer?s record, and records are deleted or inserted in the AD and/or Novell tables as necessary.

    Check if there is any error in the communication log.

    1. Log in to the registry and look for "tracedisabled" on the following registry path.

     HKEY_LOCAL_MACHINE\SOFTWARE\GuardianEdge\Trace\TraceSinks\DBSink\GuardianEdge.ADSync &
     HKEY_LOCAL_MACHINE\SOFTWARE\GuardianEdge\Trace\TraceSinks\FileSink\GuardianEdge.ADSync
    2. Modify the string value for "tracedisabled" to 0 for both
    3. Restart the AD Sync services.
    4. The AD Sync log will get generate under "C:\Program Files\GuardianEdge\Management Server\Services\Logs" with the name "GuardianEdge.ADSync.0001.txt"



  • 6.  RE: Removing a PC from the Management Console

    Posted Apr 08, 2011 09:47 AM

    Steps to get the log is also same for SEE, the file name will be different



  • 7.  RE: Removing a PC from the Management Console

    Posted Apr 08, 2011 11:30 AM

    I will check, but dont think covers my point.  if a machine has SEE installed which is then un-installed and not re-installed, does the record get updated then?



  • 8.  RE: Removing a PC from the Management Console

    Posted Apr 17, 2011 02:18 PM

    The record is not updated, it will still show up in the console. We have AD Sync enabled in our environment and it does not remove machines that GuardianEdge (in our case) is removed from.