This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Weirdness with EC 5.0

I've noticed with moving to EC5.0 (fresh build, fresh server) that once a new IDE update is sent out to my workstations, they all report back "Unknown" in Up to date, but the Detection data and IDE columns show the most current. After like 45min-1 hour up to date changes to "Yes"


This is annoying because i have my threshold for out of date alerts set to like 75% and it always triggers when a new IDE is available. I'm only using one update (Primary) and no secondary.

Thoughts?

:19953


This thread was automatically locked due to age.
Parents
  • Hi,

    An "Unknown" state basically means the "Packages" table in the SOPHOS datatabse (SOPHOS50 in this case) is not being updated by SUM before the client that shows as "Unknown" updates and sends in a status messages.  This is possible based on timings.

    That's to say, when SUM updates, at the end of the update (has to be successful) it sends in a status message, this is processed by the management service and the packages table gets updates with the latest package information.  This update comprises of the following combination of information: ProductID, SAV Version, VirusDataVersion, IDEChecksum .  You can identify information in the packages table as having come in from SUM rather than a client as the records have a rollout number of 99999999 .

    So as SUM updates the share before the client can update, the SUM status usually beats the client's status.  If the client's status arrives first, there is no record in the packages table that matches what the client has so a new record is created for the clients combination.  As the server can't compare it against the "authority" of a SUM maintained record it has to say it is 'Unknown' at least until the SUM status comes in, matches the clients combination and then "takes over" the record by setting the rolloutnumber to 99999999.

    Now if you have a SUM which updates a number of shares,  The SUM only sends in a status update at the end of the deployment to the shares, so it is possible for a client who updates from share1 before SUM has populated share 5 and sent in a status message.

    If you think this is happening you could create a registry DWORD called ‘‘‘‘UpToDateLatencyMins’’’’ in the registry entry [HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EE\Management Tools] , maybe set it to 60 and see how things change.  You would need to restart the Sophos Management Service after creating the key. 

    Do you have multiple subscriptions and multiple distributions locations?

    Regards,

    Jak




     

    :19983
Reply
  • Hi,

    An "Unknown" state basically means the "Packages" table in the SOPHOS datatabse (SOPHOS50 in this case) is not being updated by SUM before the client that shows as "Unknown" updates and sends in a status messages.  This is possible based on timings.

    That's to say, when SUM updates, at the end of the update (has to be successful) it sends in a status message, this is processed by the management service and the packages table gets updates with the latest package information.  This update comprises of the following combination of information: ProductID, SAV Version, VirusDataVersion, IDEChecksum .  You can identify information in the packages table as having come in from SUM rather than a client as the records have a rollout number of 99999999 .

    So as SUM updates the share before the client can update, the SUM status usually beats the client's status.  If the client's status arrives first, there is no record in the packages table that matches what the client has so a new record is created for the clients combination.  As the server can't compare it against the "authority" of a SUM maintained record it has to say it is 'Unknown' at least until the SUM status comes in, matches the clients combination and then "takes over" the record by setting the rolloutnumber to 99999999.

    Now if you have a SUM which updates a number of shares,  The SUM only sends in a status update at the end of the deployment to the shares, so it is possible for a client who updates from share1 before SUM has populated share 5 and sent in a status message.

    If you think this is happening you could create a registry DWORD called ‘‘‘‘UpToDateLatencyMins’’’’ in the registry entry [HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EE\Management Tools] , maybe set it to 60 and see how things change.  You would need to restart the Sophos Management Service after creating the key. 

    Do you have multiple subscriptions and multiple distributions locations?

    Regards,

    Jak




     

    :19983
Children
No Data