ISL04 : Troubleshooting SEP 12.1 Marcus Brownell (RPM) & Martial Richard (TFE)



Similar documents
UP L13: Leveraging the full protection of SEP 12.1.x

Symantec Endpoint Protection 11.0 Architecture, Sizing, and Performance Recommendations

Symantec AntiVirus Corporate Edition Patch Update

Hyper-V Installation Guide for Snare Server

How To Set Up A Shared Insight Cache Server On A Pc Or Macbook With A Virtual Environment On A Virtual Computer (For A Virtual) (For Pc Or Ipa) ( For Macbook) (Or Macbook). (For Macbook

W H I T E P A P E R : T E C H N I C A L. Understanding and Configuring Symantec Endpoint Protection Group Update Providers

Getting Started. Symantec Client Security. About Symantec Client Security. How to get started

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

Getting Started with Symantec Endpoint Protection

Symantec LiveUpdate Administrator. Getting Started Guide

Securing the endpoint and your data

SIMATIC. Process Control System PCS 7 Configuration Symantec Endpoint Protection (V12.1) Preface 1. Virus scanner administration 2.

Altiris IT Analytics Solution 7.1 SP1 from Symantec User Guide

Compatibility with Encryption Products

DameWare Server. Administrator Guide

Best Practices for Running Symantec Endpoint Protection 12.1 on the Microsoft Azure Platform

Getting started. Symantec AntiVirus Corporate Edition. About Symantec AntiVirus. How to get started

Getting started. Symantec AntiVirus Corporate Edition. About Symantec AntiVirus. How to get started

AXIS 70U - Using Scan-to-File

IBM WebSphere Partner Gateway V6.2.1 Advanced and Enterprise Editions

DX8100 Series Symantec AntiVirus Corporate Edition Installation Instructions. Version

Enterprise Vault Installing and Configuring

Getting started. Symantec AntiVirus Business Pack. About Symantec AntiVirus. Where to find information

Universal Management Service 2015

Symantec Mail Security for Microsoft Exchange Getting Started Guide

Symantec Endpoint Protection (SEP) 11.0 Configuring the SEP Client for Self-Protection

Sage HRMS 2014 Sage Employee Self Service Tech Installation Guide for Windows 2003, 2008, and October 2013

Symantec Endpoint Protection Analyzer Report

Symantec Mail Security for Microsoft Exchange

Best Practices for Running Symantec Endpoint Protection 12.1 on Point-of- Sale Devices

Use QNAP NAS for Backup

Symantec Endpoint Protection Small Business Edition Getting Started Guide

Symantec Endpoint Protection Small Business Edition cloud Getting Started Guide

Citrix Lab Manager 3.6 SP 2 Quick Start Guide

Wise Package Studio 8.0 MR1 Release Notes

Altiris Patch Management Solution for Windows 7.1 from Symantec Release Notes

Version 3.8. Installation Guide

Reducing Risk Through Effective Certificate Management

Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2)

Xcalibur Global Version 1.2 Installation Guide Document Version 3.0

Installation Notes for Outpost Network Security (ONS) version 3.2

Lepide Exchange Recovery Manager

2X Cloud Portal v10.5

Mobility Services Platform Software Installation Guide

Administration of Symantec Endpoint Protection

Symantec Endpoint Protection Getting Started Guide

ez Agent Administrator s Guide

Symantec Event Collector 4.3 for Microsoft Windows Quick Reference

How To Install Safari Antivirus On A Dv8000 Dv Recorder On A Pc Or Macbook Or Ipad (For A Pc) On A Microsoft Dv8 (For Macbook) On An Ipad Or Ipa (

MobileStatus Server Installation and Configuration Guide

Symantec Endpoint Protection Small Business Edition Installation and Administration Guide

Windows Azure Pack Installation and Initial Configuration

Symantec Mail Security for Microsoft Exchange

Rebasoft Auditor Quick Start Guide

SA Citrix Virtual Desktop Infrastructure (VDI) Configuration Guide

Step-by-Step Guide to Setup Instant Messaging (IM) Workspace Datasheet

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

Symantec Enterprise Vault Technical Note. Troubleshooting the Monitoring database and agents. Windows

Symantec Event Collector for Kiwi Syslog Daemon version 3.7 Quick Reference

Keynote DeviceAnywhere/HP Application Lifecycle Management (HP ALM/QC) Integration Guide. TCE Automation 5.2

Getting started. Symantec AntiVirus Corporate Edition 8.1 for Workstations and Network Servers

For Active Directory Installation Guide

HP Business Availability Center

Crystal Reports Installation Guide

Enterprise Vault Whitepaper Move Archive Feature Overview

NetWrix Account Lockout Examiner Version 4.0 Administrator Guide

Symantec pcanywhere Administrator s Guide

Symantec Enterprise Vault Technical Note. Administering the Monitoring database. Windows

Dell UPS Local Node Manager USER'S GUIDE EXTENSION FOR MICROSOFT VIRTUAL ARCHITECTURES Dellups.com

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

To install Multifront you need to have familiarity with Internet Information Services (IIS), Microsoft.NET Framework and SQL Server 2008.

How to Provision a Polycom Phone

Recommended Solutions for Installing Symantec Endpoint Protection 12.1.x in Shared and PvD Virtual Machines

SA Citrix Virtual Desktop Infrastructure (VDI) Configuration Guide

Lepide Active Directory Self Service. Installation Guide. Lepide Active Directory Self Service Tool. Lepide Software Private Limited Page 1

Dell Client Profile Updating Utility 5.5.6

User Manual. User Manual Version

Dell One Identity Cloud Access Manager How to Configure vworkspace Integration

Using Internet or Windows Explorer to Upload Your Site

How To Set Up Safetica Insight 9 (Safetica) For A Safetrica Management Service (Sms) For An Ipad Or Ipad (Smb) (Sbc) (For A Safetaica) (

Symantec Endpoint Protection Shared Insight Cache User Guide

Thinspace deskcloud. Quick Start Guide

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

UP L17 Virtualization: Security Without Sacrificing Performance

LAE 5.1. Windows Server Installation Guide. Version 1.0

Quick Install Guide. Lumension Endpoint Management and Security Suite 7.1

Additionally, you can run LiveUpdate manually to check for the latest definitions directly from Symantec:

ENTERPRISE VAULT 9.0 FEATURE BRIEFING

Quick Start to Evaluating. HP t5630w, HP t5730w, HP gt7720

User Manual. Copyright Rogev LTD

An Oracle White Paper September Oracle WebLogic Server 12c on Microsoft Windows Azure

HPSM Integration Guide

AdminStudio Installation Guide. Version 2013

QAD Enterprise Applications. Training Guide Demand Management 6.1 Technical Training

Symantec Endpoint Protection Integration Component 7.5 Release Notes

Symantec Mail Security for Microsoft Exchange

User Manual Version User Manual A20 / A50 / A100 / A250 / A500 / A1000 / A2000 / A4000

Business Process Management IBM Business Process Manager V7.5

Backup Exec 15. Quick Installation Guide

Transcription:

ISL04 : Troubleshooting SEP 12.1 Marcus Brownell (RPM) & Martial Richard (TFE) ISL04 1

Symantec Endpoint Protection Investigator Curriculum 2

Methodology ISL04 WORLDWIDE TECHNICAL SYMPOSIUM 2012 3

From I have a problem to what problem? Gather evidence Research Fix & Validate User s opinion ;) Log Behavior reproduced Tools Debug Knowledge base Phone a friend Re boot Re configure Re consider design Upgrade 4

Interacting with support Gather logs and screenshots Sum up the issue in a few sentences and be as precise as possible Run SymHelp or the Symantec Support Tool Get your customer ID or Entitlement Nr ready 8

SEP SOS 101 Common pain points, logs and tools to know about ISL04 WORLDWIDE TECHNICAL SYMPOSIUM 2012 9

SEP infrastructure pain points Content INTERNET Liveupdate Database SEPM Management & Content Content & Reputation SEP Clients 10

Common root causes Misconfiguration Network or system issue Implementation issue (system requirements / architecture ) Specific environment Bug An issue is not always a bug. A bug is always an issue. 11

SEPM Hot places Content Communication Distribution Monitor View Management Server List Client deployment report \inetpub\content Location awareness settings \inetpub\packages \data\outbox\agent\<groupid> Firewall policy Msi logs (local on the endpoint) Httpd log \data\outbox\agent\<groupid> Tomcat logs 12

SEP client hot places Content Communication Distribution \inbox Troubleshooting screen \Connection C:\temp Log.lue Windows & SEP firewall %temp%\sep_inst.log (msi) Smc debug log Sylink.xml System resource Rtvscan.log Smc debug log Event log 13

Automated support tools SEP Support tool From help Menu No Windows 8 /2012 support SEP Only Symhelp From KB All windows versions Multiples products 14

SymHelp switches -h Display this help page -noup Do not check for an updated version of Symantec Help -disable Disable debug mode for installed products. Use -enable to enable debug mode. -enable Enable debug mode for installed products. Use -disable to disable debug mode. -lang language-id Set the display language using the two-letter ISO 639-1 language ID -s Run Symantec Help in silent mode. -healthchk Scan for the health of all installed products. -prechk Scan for pre-install requirements of all supported but not installed products. -bestchk Scan for best practices in all installed products. -forsupport Collect full data for support. -open filename Open an existing report. -dest Destination directory. If not specified, the default destination is c:. Set the default location for saving reports. -ftpup Perform the update check using only FTP. -httpup Perform the update check using only HTTP. -wizno Do not run in wizard mode. -wizprod Run in product wizard mode. 15

SEP Support Tool -client Run a client pre-install report -console Run a console pre-install report -debug Enable debug mode for troubleshooting -def Collect data on virus definitions -fg Collect full data -h Display this help page -lp Collect load point data -msiapifeatures Use legacy method to collect MSI-installed product information -noup Do not check for an updated version of the tool -out dir Set the default location for saved reports -s Run in silent mode -spe Starts the Support Tool with the Power Eraser Option selected -speonly Runs the Support Tool silently with Power Eraser -spexml Creates an XML version of the Power Eraser results -qg Collect quick data -version n Set the target version of SEP/SPC for the pre-install reports (11, 12 or 12.1) 16

-deepdata : WPP Logging with SEP support tool WPP logging (new in SEP 12.1) collects logs for the following: Symantec Security Technology and Response (STAR), which includes file-, network-, behavior-, reputation-, and remediation-based technology Live Update Engine (LUE) SONAR The Symantec Endpoint Protection installer The benefit of moving to WPP logging is that WPP supports kernel-mode and user-mode tracing. For example: Auto-Protect and SONAR use kernel-mode logging. The client UI and LUE use user-mode logging. WPP logs are only interpreted by Symantec Technical Support. 17

Exercise 1 Communication breakdown ISL04 WORLDWIDE TECHNICAL SYMPOSIUM 2012 18

Synopsis Time to complete 20 mins Windows XP SP3 SEP freshly installed Never connected to the SEPM No green dot Windows login Administrator Symc4now! SEPM Login admin Symc4now! 19

Exercise 2 Content update ISL04 WORLDWIDE TECHNICAL SYMPOSIUM 2012 20

Synopsis Time to complete 25 mins Client AV update is out of date: Fix the issue. DO NOT RUN LIVEUPDATE ON THE SEPM Windows login Administrator Symc4now! SEPM Login admin Symc4now! 21

Exercise 3 Freeform lab ISL04 WORLDWIDE TECHNICAL SYMPOSIUM 2012 22

Synopsis Time to complete 35 mins Break something on your SEPM (service set to manual, folder rights ) Switch with your neighbor Use the SymHelp tool and other tools to figure out the issue. Windows login Administrator Symc4now! SEPM Login admin Symc4now! 23

Next steps Bookmark Symantec support & security response site SYMC only :Get VM and lab guides (symapps) Everyone: Slides and lab guides SymIQ for Partners Practice troubleshooting methodology as soon as you can. 24

Digging Further SymIQ for Partners Release notes & manuals KB articles Connect forum Connect calls for Technical Champions 25

Commercial break. 26

Congratulations! You are now officially SEP Investigators However there s always room for improvement. Any questions? >_ 27

Thank you! Martial RICHARD & Marcus Brownell Martial_richard@symantec.com Marcus_brownell@symantec.com Copyright 2011 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied, are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice. ISL04 28