Jump to content

RyanTsai

Members
  • Posts

    48
  • Joined

  • Last visited

Everything posted by RyanTsai

  1. OP specifically said he's using Endpoint Antivirus, so Web Control is not available. Only other option would be enabling diagnostic logging, but AFAIK these logs don't get passed to ERA.
  2. That was over a year ago, the log out time can be changed for all users including Administrator in user preferences at least from ERA 6.2 onwards.
  3. Unfortunately this really isn't a good option since there will be around 20000 PCs connecting to the server, and no reliable way to tell which PC belongs to which group.
  4. I've got a client with ERA 6.4 and they have created around 250 static groups. They want to create different all-in-one installers for each of groups so that different branches automatically joins appropriate static group after installation. As you can imagine manually creating these all-in-one installers via the web interface is slow and error-prone, so I would like to ask if there's a faster/better way to do this? Remote push/GPO deployment is out of the question. Any suggestions are welcome, thanks in advance!
  5. Try using the steps here to uninstall in safe mode then re-install: hxxp://support.eset.com/kb2289/?viewlocale=en_US
  6. Do you get any errors when pressing "Update" ? In any case try go to Settings - Advanced Settings - Update - Clear Update Cache, press update again and see if it updates successfully, if not try a re-install. ESET does not provide offline virus DB downloads.
  7. I've seen cases where all-in-one installer generated by ERA doesn't want activate for some reason. If you enter product key directly on the client, you get an "ACT. 21 Internal error", remote activation tasks would fail too, most likely due to the same issue. Some suggestions for you to try: 1. Delete the license key on ERA, added it again, and then re-create the all-in-one package (you can ditch the old ones as they're probably already botched) 2. Create the all-in-one package without the license, then use the activation task for activation.
  8. Try this update: https://forum.eset.com/topic/9695-eset-remote-administrator-web-console-version-642810-has-been-released/
  9. In the case of false positive, how to recover files from the quarantine? it seems I can only delete files quarantined by EVS in quarantine management.
  10. Hi, I have a question regarding EVS. Where are the quarantined files stored in EVS? EVS Appliance or Virtual Agent Host? Is there any way to recover quarantine files? I tried a Upload Quarantined file client task but failed with "Ignoring invalid task for VAgentHost"
  11. It should be parameter --silent and also --avr-disable may be interesting as it disables AVRemover. Just wondering if there's any other parameter for the bundled installer similar to msiexec /passive which shows a progress bar.
  12. Hi, I have a customer interested in deploying EVS for their VMWare vSphere servers. However they have a question regarding DRS and HA, what happens to EVS when DRS/HA kicks in and automatically migrate VMs to other hosts? Is it correct to assume that as long as every host has vShield Endpoint enabled and EVS appliance deployed, nothing will change, VMs still gets protected, and no duplicate entry for agentless protected VM will appear in ERA ?
  13. Don't know the technical details but wouldn't that require either constant connection or polling at specified intervals? doesn't sound like a good idea for corporate firewalls. How about some kind of management mode? for instance when you switch on management mode(provide a way on both server side and client side, obviously on server side this is like setting the 60 second policy), then Agent will force it's connection interval at 60 seconds, then automatically revert back to the original connection interval after 1 hour or something, in case people forget to unset it. In fact this would be a good idea for deployment too, make management mode the default and have a sensible default connection interval like 10 minutes. I've seen many people not applying connection interval policies and left it on default(I believe Agent default is 20 seconds) even when they have already deployed hundreds of clients.
  14. Which task are you using? AFAIK Software Install task only supports .MSI format installers. For .exe ones you can try Run Command task.
  15. Aftering upgrading the Agent on the Shared Local Cache appliance to 6.4.293.0, ERA started report that "Product is Installed but not running": I managed to get the Agent trace log on the appliance, this is what it says: 2016-09-08 16:21:24 Error: CEslcConnectorModule [Thread 7f02677fe700]: Connecting to '/opt/eset/eslc/sbin/eslc_daemon' failed with: Connection refused. EES/EAV daemon is not probably running 2016-09-08 16:21:43 Error: CEslcConnectorModule [Thread 7f02677fe700]: Connecting to '/opt/eset/eslc/sbin/eslc_daemon' failed with: Connection refused. EES/EAV daemon is not probably running The appliance is still working properly, I can see the number of queries being changed, so perhaps there's a compatibility issues with Agent 6.4 on Linux and ESLC 1.0.16.0?
  16. AFAIK without web protocol filtering ESET Live Grid(Provides quicker protection against 0-day viruses) will also be disabled for downloads. Also there's a URL blacklist inside virus database which blocks known malware URLs, without protocol filtering you can still get infected when new undetectable malware are downloaded from these URLs. In general it should be enabled as long as there's unrestricted web browsing on the target computer.
  17. If you already have computers in different static groups (e.g. synced from AD) and want to automatically apply different licenses to different static groups, you can just create dynamic groups under these static groups with the same "Unactivated Computers" template, then hook different activation tasks to these child dynamic groups. These dynamic groups will apply only to computers in parent static groups.
  18. Hi, Just want to ask Is the ERAS 5.x mirror server compatible with 6.x clients?
  19. Hi Martin, Thanks for the reply. How do I enable full msiexec trace logging? running msiexec with /L*v produces a log file but doesn't provide much more information other than the same EraAgentSvc startup error. Agent service is not present once installation is finished. Here are the error entries in event logs (sorry screenshots in Chinese) Error codes: 7000, 7009 No ESET Product already installed, and PC is relatively clean with only few apps installed. Running ERAAgent.exe during installation (when the failed to start service error message is displayed and installation is halted) shows another error message: Roughly it says "Applicaton cannot be correctly started, error 0xc000007b, press OK to close application" Thanks a lot for the help~
  20. Hi there, I have a particular machine which for some reason the Agent cannot be installed, during installation an error message saying that ERAAgentSvc failed to start, and then setup fails. Obviously we're sure setup is running under an account with Administrator rights, also tried executing setup with Administrator privileges but result is the same. I can see that when the error message appears, ESET Remote Administrator Agent does appear in the list of services, however it cannot be started, event logs says it failed t respond in a timely manner. Also there are not logs created under C:\ProgramData\ESET\RemoteAdministrator\Agent\EraApplicationData\Logs so there's no way to know what is going on. OS: Win7 SP1 x64 Can anybody help? what other information is needed to troubleshoot this problem?
×
×
  • Create New...