Jump to content

rgoldman

Members
  • Content Count

    25
  • Joined

  • Last visited

Everything posted by rgoldman

  1. Getting high memory usage (6-11GB) by ekrn Version: 7.1.12010.0 I'm trying a procdump64 -ma ekrn but getting an error 8007000D Any suggestions? Thanks
  2. Ok so I feel dumb! I guess maybe after I rebooted the server they re appeared or something but I was viewing it wrong. They we're not in there before 🤪
  3. I'm about to contact support. Nothing like that was updated recently. Everything has been working fine. I was in ESMC casually browsing/checking/performing tasks. When the error popped up, the page was actually idle. Thanks
  4. All of my custom policies have disappeared. I was prompted in ESMC that, "Failed to load all applied policies" After that none my policies are there. I've restarted service, and rebooted the entire server, no change, no other errors. Any help? Thanks!
  5. Thanks. I also noticed some abnormalities in that policy so I've started a fresh basic policy and we'll see how it goes.
  6. [23:52:26 PM] ESET Log Collector v4.0.2.0 (12/9/2019) - 64 bit [23:52:26 PM] Copyright (c) 1992-2019 ESET, spol. s r.o. All rights reserved. [23:52:26 PM] [23:52:26 PM] Detected product type: eea [23:52:29 PM] ============================== [23:52:29 PM] ESET logs collection mode: Filtered binary [23:52:29 PM] Number of days to collect target files and log records for: 30 [23:52:29 PM] Saving metadata to C:\Users\user\AppData\Local\Temp\elc41D3.tmp [23:52:29 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc41D3.tmp -> metadata.txt [23:52:29 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc41D4.tmp -> info.xml [23:52:29 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc41D5.tmp -> features_state.txt [23:52:29 PM] === Running processes (open handles and loaded DLLs) === [23:52:29 PM] Exporting... [23:52:31 PM] OK [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc41D6.tmp -> Windows/Processes.txt [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc41D7.tmp -> Windows/ProcessesTree.txt [23:52:31 PM] === Drives info === [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc480F.tmp -> Windows/drives.txt [23:52:31 PM] Exporting volume information... [23:52:31 PM] OK [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc4820.tmp -> Windows/volumes.txt [23:52:31 PM] === Devices info === [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc4AA0.tmp -> Windows/devices/setupClasses.txt [23:52:31 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc4AC1.tmp -> Windows/devices/interfaceClasses.txt [23:52:31 PM] === Services Registry key content === [23:52:31 PM] Exporting... [23:52:32 PM] OK [23:52:32 PM] Adding file: C:\Users\user\AppData\Local\Temp\elc4AC2.tmp -> Windows/Services.reg [23:52:32 PM] === Application event log === [23:52:32 PM] Exporting... [23:52:32 PM] Windows event logs could not be exported in evtx format. Exporting in xml format... [23:52:32 PM] ERROR: Failed to open event log [23:52:32 PM] [23:52:32 PM] Removing temp files... [23:52:32 PM] [23:52:32 PM] ============================== [23:52:32 PM] An error occured during collection of files. See the log for more info. Updated and everything fine it seems. But when I run the collector I get an error. I tried Defaults, 1 and 30 days, same error.
  7. Understood. I'm leaning towards policy based mode to heavily manage some devices for security. Does policy based mode use file hashes or filenames? Thanks
  8. Can someone point me to a good and thorough resource/info on setting up HIPS. I'm testing it with a few devices in learning mode and then policy mode after that but not sure if I'm understanding right. Thanks for any info. Cheers.
  9. Hello I have one computer that is in a group of which I have set to receive email notifications. I removed that policy and assigned new policy that has email notifications disabled yet I still receive emails. I have also "Muted" the computer and I still receive emails. What exactly does "Mute" do and should I still receive emails if I have muted a device? I read in Help that it will stop communicating with ESMC but doesn't clearly say about email notifications etc. Thanks
  10. Thanks guys, and sorry I thought I had email notifications for replies on and I haven't checked the forum until now. @Nightowl It's been doing this a while, like before Windows 7 went out of support etc. Sorry I know I should have fixed it before now but the client is working fine, it's just reporting a date in the future as an error or something, not sure. @MichalJ Yes the time is correct on the workstation, I've checked numerous times and settings during checkout/maintenance. @Marcos Attaching a screenshot of the Endpoint itself, is that what you're asking about?
  11. Hello I have a workstation, running Windows 7 Pro, theres always a error on it in ESMC, saying its not up to date etc. But what's weird is it under status/last occurred is always a date in the future. I don't understand. I've updated the installation multiple times, done maintenance on the OS, reset winsock, cleanup etc. and it's still doing this, any suggestions? Screenshot is attached. Thanks Reggie
×
×
  • Create New...