Endpoint Protection

 View Only
Expand all | Collapse all

LiveUpdate Cannot update virus definitions

  • 1.  LiveUpdate Cannot update virus definitions

    Posted May 19, 2022 03:30 PM
      |   view attached

    Hello!
    Symantec Endpoint Protection 14.3 RU4 cannot update virus definitions.
    Last virus definitions is in attachment

    LiveUpdate log show
    _________________________________________________________________
    17 may 2022 22:14:44 : LiveUpdate succeeded. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : LiveUpdate finished running. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : LiveUpdate successfully updated the content. Return code = 0. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.2 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win64 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SEPM LiveUpdate Database 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Detection and Response 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win32 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Detection and Response 14.2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.2 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection Win64 14.3 RU4 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection Manager Content Catalog 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Revocation Data 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win32 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win32 14.3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Attack Surface Reduction 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win64 14.3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Browser Extension Win32 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Browser Extension Win64 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Virus and Spyware definitions SDS Win32 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SONAR Heuristics engine 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Advanced Machine Learning (Static) content Win32 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Threat Defense for AD Data 14.2 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win32 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Threat Defense for AD Data 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Detection and Response 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win64 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Virus and Spyware definitions SDS Win64 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 12.1 RU5. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Advanced Machine Learning (Static) content Win64 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Power Eraser Definitions 14.0. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win32 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection Manager API 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Application Control Data 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Virus and Spyware definitions SDS Win64 (reduced) 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Allow List 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SONAR Heuristics engine 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SONAR Heuristics engine 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SEPM Data 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection Win32 14.3 RU4 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win64 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Power Eraser Definitions 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection Manager Metadata 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Detection and Response 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Policy Command Handler 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Application Control Data 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Common Network Transport Library and Configuration 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Protection LINUXRPM 12.1.7454.7000 (English) [90.2]. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Virus and Spyware definitions SDS Win32 (reduced) 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Endpoint Detection and Response 14.0. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 12.1 RU6 MP8. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for SONAR Heuristics engine 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for AP Portal List 14.3 RU3. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Web and Cloud Access Protection 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Policy Command Handler. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Centralized Reputation Settings 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Virus and Spyware definitions SDS Win64 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Symantec Endpoint Foundation Win64 14.3 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Submission Control signatures 14.3 RU1. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Extended File Attributes and Signatures 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Advanced Machine Learning (Static) content Win64 14.2 RU2. [Site: My Site] [Server: W12]
    17 may 2022 22:14:44 : No updates found for Intrusion Prevention Signatures 14.0. [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Virus and Spyware definitions SDS Win64 (reduced) 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Windows Host Integrity Content 14.3 RU4. [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win64 14.3 RU4 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win64 14.3 RU3 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win64 14.3 RU2 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win32 14.3 RU4 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win32 14.3 RU3 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:14:43 : No updates found for Symantec Endpoint Protection Client Patch Win32 14.3 RU2 (English). [Site: My Site] [Server: W12]
    17 may 2022 22:12:46 : LiveUpdate has been launched. [Site: My Site] [Server: W12]
    17 may 2022 22:12:46 : Download started. [Site: My Site] [Server: W12]
    ___________________________________________________________________________
    I try

    "C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\LuCatalog.exe" -update
    "C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\LuCatalog.exe" -cleanup
    but no result.
    Can you help me to solve this problem.
    Thank you in advance.



  • 2.  RE: LiveUpdate Cannot update virus definitions

    Posted May 23, 2022 03:45 PM
     Join the question. Updates take place only when downloading jdb files from the site. Moved the database to a test server, but the updates don't go through automatically either. Does tech support have any comments on this?



  • 3.  RE: LiveUpdate Cannot update virus definitions

    Posted May 27, 2022 12:23 AM
    Hi 

    Could you try open the SEP (on the server where you have installed SEPM) - change settings - client management settings - uncheck protect symantec security - then re- run live update.


  • 4.  RE: LiveUpdate Cannot update virus definitions

    Posted May 27, 2022 08:36 AM
    Hello! Disabled on the client and in the client policy in SEPM Uncheck Protection Symantec security software from being tampered with or shutdown. No changes, the database has not been updated.



  • 5.  RE: LiveUpdate Cannot update virus definitions

    Posted May 27, 2022 03:12 PM
    Hello.
    In my configuration client (SEP) does not installed on server (SEPM).


  • 6.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 01, 2022 12:18 PM
    Hello.
    Has anyone solved this problem?


  • 7.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 02, 2022 08:51 AM

    I also am having this issue

    Specifically symantec SES which I manage through the cloud, and not an onsite Server installation.

    I have 25 or so systems, and some of them claim to not be fully updated and others do,
    Which ones "complain" varies from week to week so it is not an individual PC configuration.

    If I push updates from the web - I see no changes.  If I go them manually and open Symantec Shield icon - click [Live Update...] link - eventually they end up showing "up to date".

    I compared the web console's "Belief about what defnitions" are on a "failing" PC and a "good" PC.  Of the 21 updates that Live Update checks, some apparently are not listed...however  "Malware Protection" version on "failing" PC showed  2022-04-07 and "good" showed 2022-05-28.

    I compared the two reports side by side, for this pair, that was the only difference.  Other pairings might be different elsewhere.




  • 8.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 03, 2022 10:28 AM
    Hello.
    Does anyone opened problem ticket in Symantec support?


  • 9.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 07, 2022 01:01 PM
    Recently, I also encountered an update problem here, but it seems different from your case.

    The root cause of my problem is that the security settings of the SEP client affect SEPM's processing of updates.

    From the content of your log, the problem should come from the LiveUpdate aspect.
    My SEPM cannot update the virus definition code after upgrading from 14.3 MP1 to ru4. Use JDB file updates or LiveUpdate updates are not available. The download was successful, but SEPM was unable to update its own definition code.
    After opening the case, two solutions are given. I solved the problem using scenario 1 (disable SEP client tamper proof). But it seems different from your case. You can try scheme 2。

    (The above words are translated by translation software, which may inevitably lead to mistakes and omissions. Please forgive me.)

    =========================================

    Noted. Please try the following workaround below. 


    Workaround 1Disable the Protection Symantec security software from being tampered

    1. Open the SEP client UI from the SEPM server. 
    2. Click Change Settings > Client Management > Tamper Protection Tab > Uncheck "Protection Symantec security software from being tampered"
    3. Click Ok to save and close the SEP client UI. 


    Now, Login to SEPM console and manually run Download LiveUpdate again. Monitor the status and let me know the result. 

    If workaround 1 does not resolve the issue, please try workaround 2 below. 


    Workaround 2: Manually purge the corrupted definition/content from Symantec Endpoint Protection Manager (SEPM)

    Please follow the details steps below to replace the old content and definitions.

    https://knowledge.broadcom.com/external/article/184206/how-to-manually-purge-definitions-for-th.html






  • 10.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 07, 2022 01:01 PM
    Two weeks ago, since I upgraded SEPM (version 14.3 MP1) to version ru4, my SEPM was unable to update the virus definition code. Whether it is LiveUpdate update or manual download JDB file update failed.



    I opened a case and the after-sales service provided two solutions. At present, my problem has been solved. However, the root cause of my problem is that the security settings of the SEP client affect SEPM's processing of updates. From the content of your log, the problem should come from the LiveUpdate aspect. It is recommended that you try scheme 2 again according to the steps

    (the above words are translated by translation software, which may inevitably lead to mistakes and omissions. Please forgive me!)

    ======================================

    Noted. Please try the following workaround below.


    Workaround 1: Disable the Protection Symantec security software from being tampered

    1. Open the SEP client UI from the SEPM server.
    2. Click Change Settings > Client Management > Tamper Protection Tab > Uncheck "Protection Symantec security software from being tampered"
    3. Click Ok to save and close the SEP client UI.

    Now, Login to SEPM console and manually run Download LiveUpdate again. Monitor the status and let me know the result.

    If workaround 1 does not resolve the issue, please try workaround 2 below.


    Workaround 2: Manually purge the corrupted definition/content from Symantec Endpoint Protection Manager (SEPM)

    Please follow the details steps below to replace the old content and definitions.

    https://knowledge.broadcom.com/external/article/184206/how-to-manually-purge-definitions-for-th.html



  • 11.  RE: LiveUpdate Cannot update virus definitions

    Broadcom Employee
    Posted Jun 03, 2022 11:23 AM

    Hi Dan,

    Your issue is different. There is a defect that will be resolved in 14.3 RU5. ETA is this month.



    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------



  • 12.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 07, 2022 01:00 PM
    Hello.
    I installed SEP client on SEPM server , but it does not solve problem.
    Any ideas?


  • 13.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 10, 2022 03:07 AM
    Have you tested the second scheme I mentioned?
    Workaround 2: Manually purge the corrupted definition/content from Symantec Endpoint Protection Manager (SEPM)

    Please follow the details steps below to replace the old content and definitions.

    https://knowledge.broadcom.com/external/article/184206/how-to-manually-purge-definitions-for-th.html



  • 14.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 15, 2022 08:16 AM
    Hello! Made according to the instructions https://knowledge.broadcom.com/external/article/184206/how-to-manually-purge-definitions-for-th.html, the database is not updated.



  • 15.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 15, 2022 09:39 AM
    Hello.
    Yes, i try manually purge the corrupted definition/content from Symantec Endpoint Protection Manager (SEPM), but it does not solved my problem.
    Any ideas?


  • 16.  RE: LiveUpdate Cannot update virus definitions

    Posted Jun 16, 2022 05:11 AM
    Hello, it is recommended to refer to the steps in the following materials for troubleshooting.

    If the problem still cannot be solved, please submit a case to the after-sales technical support department for solution.

    Troubleshoot common LiveUpdate issues (with flowchart)
    https://knowledge.broadcom.com/external/article?legacyId=tech95790

    Troubleshoot LiveUpdate and definition issues with Endpoint Protection Manager
    https://knowledge.broadcom.com/external/article?legacyId=TECH105924
    ==================================
    Troubleshooting Symantec Endpoint Protection
    https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/troubleshooting-v58233805-d77e6.html