Endpoint Protection

 View Only
Expand all | Collapse all

FILE REPUTATION LOOKUP ALERT

  • 1.  FILE REPUTATION LOOKUP ALERT

    Posted Apr 17, 2015 06:58 AM

    hi all


    ive started receiving file reputation lookup alerts for a couple of servers. when it first started it was only for 1 server now another has popped up.

    i found the following forum post about this and followed the suggestions but i wasnt able to resolve the issue and its still happening

     

    https://www-secure.symantec.com/connect/forums/reputation-check-unproven-files-failed-because-network-errors-last-3-days

     

    our product version is 12.1.5337.5000 

     

     

    does anybody know how to resolve this?



  • 2.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Apr 17, 2015 07:02 AM
    It means the client couldn't connect to the reputation service. Usually this corrects itself. Do these servers have internet access?


  • 3.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Apr 17, 2015 07:09 AM

    yes both servers have access to the internet

    there have been no changes in our network otherwise all the servers would be reporting issues :/

     

     



  • 4.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Apr 17, 2015 07:59 AM

    This is usually a one time issue and it may conmnect next time around, has it been constant for these servers?



  • 5.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Apr 17, 2015 12:37 PM

    its been happening to one of the servers for a while now..

     

    the 2nd server has only popped up in the last few days

     

     



  • 6.  RE: FILE REPUTATION LOOKUP ALERT

    Broadcom Employee
    Posted Apr 20, 2015 05:50 AM

    Could you share the alert message details/screenshot?



  • 7.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Apr 22, 2015 06:13 AM
      |   view attached

    hi

    sorry for the late reply i missed the email notification

    here is the notification we get emailed.. let me know if you need anything else

     

     

     

     



  • 8.  RE: FILE REPUTATION LOOKUP ALERT

    Broadcom Employee
    Posted Apr 27, 2015 09:25 AM

    Hello,

    This happens when the SEP client file reputation check operation is timing out as the external firewall blocks access to https://ent-shasta-rrs.symantec.com/mrclean

    Try the following steps:

    Note: Though these settings are not recommended I would suggest to try them to find out possible root cause.

    On the Symantec Endpoint Protection Manager (SEPM):

    1) Go to Policies > Virus and spyware protection > right click and edit the policy > Under Windows settings > protection technology > Download protection

    2) Uncheck "Enable download insight to detect potential risk in downloaded files based on file reputation"

    & Monitor subsequent alerts.



  • 9.  RE: FILE REPUTATION LOOKUP ALERT

    Broadcom Employee
    Posted May 08, 2015 08:40 AM

    Is there any update?

    OR

    If query has been resolved mark this thread as a 'Solved' with the best answer that helps you.



  • 10.  RE: FILE REPUTATION LOOKUP ALERT

    Broadcom Employee
    Posted May 22, 2015 02:10 PM

    SEP 12.1 RU6 has been released & has a bug related to File repuation alert, check if it's applicable in your case or not however I would suggest you to upgrade to SEP 12 1 RU6.

    File Reputation Lookup Alerts send malformed emails when triggered

    Fix ID: 3713171

    Symptom: File Reputation Lookup Alert notifications created after the install of Symantec Endpoint Protection Manager 12.1 RU5 sends incomplete emails when triggered and does not include details about why this email was sent.

    Solution: File Reputation Lookup Alert notifications are now created correctly and generate the expected email report.

    Reference: New fixes in Symantec Endpoint Protection 12.1.6

    https://support.symantec.com/en_US/article.TECH230558.html

    Upgrading or migrating to Symantec Endpoint Protection 12.1.6 (RU6)

    http://www.symantec.com/docs/TECH230601



  • 11.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Aug 25, 2015 07:17 AM
      |   view attached

    Dear Chetan,

     

    I am running version 12.1.6168.6000 but I am receiving the same prompts from time to time as well but not always from servers but also from the client computers. They all have internet connection and much like the starter of the thread not much else has changed across the network configuration wise.

    Also it used to be one server and now as you can see in the screen shot another server and two client machines have also joined up.

    My question about the address you provided above is which port number and what protocol should also be allowed through the firewall to make sure of the proper functionality?

    Thanks

     

     



  • 12.  RE: FILE REPUTATION LOOKUP ALERT

    Broadcom Employee
    Posted Aug 25, 2015 08:27 AM

    Under exceptions can place the URL directly, port & protocol information isn't available as per my knowledge.



  • 13.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Sep 21, 2015 10:45 AM

    I took th is advice and changed the policy setting but I'm still getting the alerts.  I don't understand what the problem is and how to make them stop or how to correct them.

     

    Dan



  • 14.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Dec 22, 2015 05:31 AM

    Hi all,

       We also getting same mail notification

         """"                

    Sent: Tuesday, December 22, 2015 9:17 AM
    To: IT Admins
    Subject: FILE REPUTATION LOOKUP ALERT

     

    Message from:
        Server name: IFSHOAVG01
        Server IP: 192.168.28.60
        Administrator Email: *********************
        Company Name: IFS
        
    6 computer reported file reputation lookup issues.  """

     

    Can any tell me the solution.



  • 15.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 04, 2016 10:33 AM

    I am also experiencing this issue.  I am running 12.1.6 MP3 (12.1.6608.6300) - Has there been a solution?



  • 16.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 04, 2016 12:28 PM

    I join the group having the same problem. Also I am running 12.1.6 MP3 (12.1.6608.6300). Help me, please



  • 17.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 04, 2016 12:30 PM

    If you check the system log on an affected client do you see an error in regards to failed submissions?



  • 18.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 04, 2016 01:15 PM

    The clients if they have connections to the network and have all the updates, how all other clients.



  • 19.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 04, 2016 04:12 PM

    I checked the system logs on some affected machines (I have 8 machines that routinely say this):

    https://goo.gl/HPa01l

    I have verified that I can access the Insight, update, and licensing servers from the affected machines as per:

    https://support.symantec.com/en_US/article.TECH162286.html

    and

    https://www-secure.symantec.com/connect/forums/computer-reported-file-reputation-lookup-issues

    Is this a bug? Is there anything else I should be trying to fix this issue?



  • 20.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Jan 06, 2016 08:06 AM

    For whatever reason it looks like our SEP client is having an issue getting out.



  • 21.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Feb 02, 2016 03:32 PM

    Hi guys I was reported a similar issue by one of my clients . They are also running the latest version of SEP that is 12.1.6 MP3 . I just want to know if this is a known issue or bug in SEP 12.1.6 MP3 . Can Symantec confirm this if it is a known issue in this version ?

     

    Thanks



  • 22.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Mar 01, 2016 07:39 AM

    HI

     

    Same exact problem just popped up on one client. 12.1.6318.6100.

    Nothing has changed on the client or nerwork.



  • 23.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Mar 29, 2016 05:01 AM

    Hi,

     

    I am also experiencing same issue - running - 12.1.6318.6100.105 please help me.



  • 24.  RE: FILE REPUTATION LOOKUP ALERT

    Posted May 03, 2016 09:47 PM

    How to find out which devices are affected by this alert?

    Message from:
        Server name: XXXXXXX
        Server IP: XXX.XXX.XXX.XXX
        Administrator Email: XXXXXXX
        Company Name: XXXXXXXX
        
    20 computer reported file reputation lookup issues. 

     

    Please advise for understanding that this is a genuine alert and not a bug that requires a fix straight away right?

    Thanks.



  • 25.  RE: FILE REPUTATION LOOKUP ALERT

    Posted May 05, 2016 04:50 AM

    Same issue cropping up for me version 12.1.6 (12.1 RU6 MP3) 6608

    Would be nice to know whats going on. Can someone update us please.



  • 26.  RE: FILE REPUTATION LOOKUP ALERT

    Posted Sep 09, 2016 07:52 AM

    dear chetan

    i have the same issue for a file reputation lookup alert ok. so you told to uncheck the following in above the comment. my qustion is if i uncheck the "Enable dowload insight to detect potential risk in downloaded file based on file reputation"  can i face any hard issue the server cant send the notification when virus is attacked on my system?

    i need to know the above instrution is good for us or not?

    and the following instrution is very good to avoid the solution but i need exact answer mr.chetan