Endpoint Protection

 View Only
Expand all | Collapse all

Green Dot Missing From Clients in SEPM

Migration User

Migration UserDec 21, 2009 10:33 AM

Migration User

Migration UserDec 21, 2009 11:30 AM

Migration User

Migration UserDec 21, 2009 11:30 AM

  • 1.  Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:05 AM
    Hello,
    the green dot is missing from the clients as viewed from the Management console after a reimage of workstation (there is no SID duplicate issues). The client/ workstation has a green dot and is recieving updates normally. When I open SEP on the workstation - Help and Support - Troubleshooting and view General Information - Group the location is incorrect and will not update. I have SEPM linked to Active Directory for the group creation. The workstation is a new vista image that was installed recently.

    SEPM 11.0.5002.333 using SQL Server 2005 together on Server 2003
    SEP 11.0.5002.333 on Vista
    Linked to AD for Groups

    There is a message I recieve when I perform a manual sync:
    The management server has detected one or more problems with entries in LDAP. These entries were ignored. This could be caused by duplicate entries or other problems.



  • 2.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:15 AM


    Try removing the Directory Server and add the LDAP server again. Then try to resynchronize the OU.


  • 3.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:24 AM

    Is that an error or a warning??

    If that is a warning then This warning is just a warning and does not indicate a genuine error.

     



  • 4.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:33 AM
    It's a warning...


  • 5.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:43 AM

    I've tried that but still I recieve the warning message. However, it is only for a couple OUs/Groups...all others sync normally. Structure and contents match Active Directory so its hard to isolate. Not sure what to check or if there are duplicate records in the database for the same computer..., I tried renaming the computer and created a fresh computer account but it still will not show in the management console with a green dot.



  • 6.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:44 AM
    As far as the warning is concerned it can be ignored

    For th Clients on online in concerned

    Remove the sync and resync it.Alos make sure that you renter the passowrd for the LDAP server


  • 7.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:54 AM

    I did remove the sync and re-added it using the correct password. still no green dot in management console. and the client still shows the wrong group location as viewed from SEP on the workstation. when i do a search in SEPM only one client resolves and that shows the correct group. seems to be a difference in what group the client thinks it should be in and what group the SEPM shows it to be in.



  • 8.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 11:02 AM
    Replace the sylink on one client and see if that helps


  • 9.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 11:08 AM
    lets go from basics if you dont mind
    can you try the secars test on the client and check if that comes okay

    Testing Communication

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007101711140148 
    if you could post a sylink log that would be fine.

    http://service1.symantec.com/support/ent-security.nsf/docid/2008041812561948



  • 10.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 11:30 AM
    Hi, Secars tests OK


  • 11.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 11:30 AM
    Hi,
    Replaced Sylink...no help


  • 12.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 11:37 AM
     take a backup of this key
    HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink
    delete this sylink key
    go to start-run
    type smc-stop
    wait for 2 mins
    smc -start
    should populate with new informationi if the client is communicating
    if that does not happen
    post the sylink log in here.



  • 13.  RE: Green Dot Missing From Clients in SEPM



  • 14.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 12:55 PM
    you need to reset the communication between client and manager
    open sepm
    click on admin
    install pacakges
    click on client install settings
    click on add.
    add a setting with checked remove client communication radio buttom
    when exporting the package, select the one you have created now with radio button
    install this package, clients should communicate.

     


  • 15.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 02:18 PM
    I've tried this before but tried again...the client installs... shows a green dot on the workstation..updates from the SEPM. But SEPM does not show a green dot for the client. The workstation SEP still shows the wrong group location.

    Where does the group information in SEP come from? Is there a way to manually edit and or delete/recreate the data source? Is there a way to view the client information in the database? Thanks.


  • 16.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 03:40 PM

    Hi,
    I deleted the sylink key ... type smc-stop; wait for 2 mins; smc -start. a new key did not appear (not sure if it was suppose to) ... I checked the SEP again and it still shows the wrong group ... and still no green dot in SEPM.

     



  • 17.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 21, 2009 10:39 PM
    Hay,

    can you check if the client's ip address is present in C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\inbox\log\ersecreg log?
    check the exsecars log at the same location as well. Search for the ip of any of the clients that have a green dot.

    Get the sylinkmonitor logs and post them here so that we can take a look at it.

    You can also refer to the following to understand the communication between sep-sepm.

    https://www-secure.symantec.com/connect/videos/about-communication-between-sep-sepm

    Aniket


  • 18.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 12:12 AM


  • 19.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 11:08 AM

    Hi Aniket,
    I'm looking in the ersecreg.log and see the old computer account name and the new computer account name with the current ip address. could this be the issue?

    Also, I see a ersecreg-1.log in the folder...?

    In the exsecars.log I'm seeing the following:

    12/22 11:03:12 [4048:4224] Open File Error G:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\outbox\agent\1C4D142BA08A281E00E5806F04902BD2\index.xml

    12/22 11:03:12 [4048:4224] Update Profile Serial Number failed! GroupID=1C4D142BA08A281E00E5806F04902BD2

    Please advise. Thank you.

    Dan.



  • 20.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 11:53 AM
    The computers I checked that have the green dot in SEPM console are listed as single entries in the ersecreg.log ... the computer accounts that are listed in pairs (next to each other)  do not have the green dot in SEPM console. Appears to be duplicate objects in the database. I guess now I have to figure out how to purge duplicates.

    Any advise would be appreciated. Thanks.

    Dan.


  • 21.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 11:53 AM
    The computers I checked that have the green dot in SEPM console are listed as single entries in the ersecreg.log ... the computer accounts that are listed in pairs (next to each other)  do not have the green dot in SEPM console. Appears to be duplicate objects in the database. I guess now I have to figure out how to purge duplicates.

    Any advise would be appreciated. Thanks.

    Dan.


  • 22.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 11:55 AM
    follow aravindkm 's suggestion of clearing the duplicates.
    should help u out. 


  • 23.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 01:55 PM
    I ran http://127.0.0.1:9090/servlet/ConsoleServlet?ActionType=ConfigServer&action=CleanClients and returned:

      <?xml version="1.0" encoding="UTF-8" ?>
      <Response ResponseCode="0" />

    Thanks...

    Dan.


  • 24.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 02:13 PM
    Let us know if that quey was able to remove the duplicate clients from SEPM.



  • 25.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 02:37 PM
    Hi,
    I ran an SQL query (below) on a computer that is not reporting or showing the greendot in SEPM and returned three different Client ID records with the same HardwareID. All three records have the same DomainID, GroupID, Policy_Mode, ComputerID, and HardwareKey. For comparison, I ran the SQL query on a computer that is reporting and shows a greendot in SEPM and returned only one record. I'm thinking duplicate records in the database is causing the issue.
    SELECT [CLIENT_ID]
    ,[DOMAIN_ID]
    ,[GROUP_ID]
    ,[POLICY_MODE]
    ,[COMPUTER_ID]
    ,[HARDWARE_KEY]
    FROM [sem5].[dbo].[SEM_CLIENT] where [HARDWARE_KEY] = 'put HardwareID from above reg key'

    I ran the above SQL query after pasting http://127.0.0.1:9090/servlet/ConsoleServlet?ActionType=ConfigServer&action=CleanClients string in the browser...which returned
      <?xml version="1.0" encoding="UTF-8" ?>
      <Response ResponseCode="0" />

    Is there another way to remove duplicates in the database via a SQL script?

    Thanks,
    Dan.


  • 26.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 03:15 PM
    I'm seeing computers with the same HardwareID... looks like an issue. Should these be unique?


  • 27.  RE: Green Dot Missing From Clients in SEPM

    Posted Dec 22, 2009 04:04 PM
    Appears that one of our departments re-imaged their computers however did not ensure that the SEP client's HardwareID key or sephwid.xml file was removed before imaging thus conflicting with each other.

    I deleted the HardwareID key and renamed the sephwid.xml file and the client popped in SEPM with all its informaiton and a nice bright green dot.

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110510364248 


    Thanks,
    Dan.


  • 28.  RE: Green Dot Missing From Clients in SEPM
    Best Answer

    Posted Dec 23, 2009 11:44 AM
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110510364248 

    1. Delete the following registry value: HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink\HardwareID  
    2. Delete the following file: Program Files\Common Files\Symantec Shared\HWID\sephwid.xml
    3. SMC -stop
    4. SMC -start

    Thanks everyone...
    Dan.