Jump to content

Miami

Members
  • Posts

    43
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by Miami

  1. Why not use the regex? With regex you can match versions the way you wish. If you need to care only about Agents version 7.2 versions use following regex  (7\.2).* 

    When you use it with application filter (to show only Eset Agents), it should match all 7.2 agent versions.

    OR, you can try to use following filter for outdated product. Its just my guess that it could work, I have not tested it, yet.

     

    0_Filter.thumb.png.3bbaececb1aa4cf4c4b31f027700c7b5.png

     

  2. I understand your situation, but to me this really looks like some policy interfere with the default policy/configuration. What I would do is to check group membership of that problematic computer. Maybe it is a member of some dynamic group and gets special agent policy. If first connection is ok, it means something is doing a configuration change and if you have more Agent policies deployed it can happen that they interfere. 

    I am guessing that info about last applied policies can be still seen in client details, same as its group membership. 

    Related to agent connection issue, I experienced a, more servers in the server list configuration b, policy interference c, DNS configuration

  3. 32 minutes ago, kvngselassie said:

    @MartinK

    There are no configuration policies in the console, all agent related policies are applied to separate groups... Also the only remote deployment task running is the agent upgrade and endpoint upgrade task... please not this also happens to devices with the latest version of the agent (7.2.1266).

    I am sure you have already double checked your policies, but this looks like Agent is being reconfigured after some time. Maybe after first connection to the server is the default policy overwritten by a forced one or the one which is closer to the computer in you structure. Is there only one server listed in Agent server list configuration? 

    For testing purposes you could create a group where no policies would be applied. Add a computer into that group and manually apply all policies that are applied to these problematic computers.

     

  4. 12 minutes ago, PuterCare said:

    Thanks, that is what I do already but I just wondered if there was a way to use a dynamic group so I can set up an automatic task just like I do for when an unactivated client joins to auto-activate it. I wasn't sure if running this task to all clients would use resources on the ESMC server or clients unnecessarily. 

    It seems if we were able to filter the Computers section like we are able to in the reports section then this is easily achievable and also I could use the "does not contain" filter on the software version with a value of "7.3." to list devices that need the urgent update. At the moment I sort my computers list by version and then manually select any that need an update. I know I can filter using specific versions but at the moment my priority is reaching at least 7.3 so we are ready for the various issues on the horizon.

    Hello, 

    we use dynamic group with following template configuration to show us all V6 Agents. I am sure you can adjust that to ver 7.

    Agent.png.68ea1b927d9064004944cd61ac690ba4.png

    Of course the group is populated on next connection of the client (agent).

  5. Question: Is it possible to to move computers between groups  with a task. If not it would be great to have such functionality in ESMC

    Detail: If we want to move computers from Lost & Found to groups created based on AD. Currently this is not possible and we have to move computers manually. 

    It would be good to have this for dynamic groups, if computer fall into such group it would be automatically moved to a desired destination group.

    Moving computers to groups at installation is not possible for us as we use only one installer for all the clients acros the globe.

     

  6. 2 hours ago, Marcos said:

    This topic is not intended for discussions, only for posting suggestions for future improvements and changes. Please open a new topic where the matter can be discussed further.

    Anyways, it's possible to set the desired static group even during deployment

    Hello Marcos,

     my post was a suggestion as that functionality is not available in ESMC, but as requested I will create a new help request in ESMC.

  7. 24 minutes ago, Marcos said:

    1, Membership in dynamic groups is dynamically evaluated by agent on clients. It doesn't happen on the ESMC server.
    2, In order to static groups with AD, use a server Static group synchronization task:

    image.png

    Should you have any questions, feel free to ask in the ESMC forum (ie. not in this topic).

    Non domain computers are not included in domain structure, they are automatically stored in Lost & Found group. Currently we do separate these clients in Dynamic groups located within "Lost & Found" and we would like to move client from these dynamic groups into our "AD structured" static groups. 

    So it looks like this:

    ALL\Lost & Found\ 

             ... pc0001

             ... pc0002

    ALL\Lost & Found\ Dynamicgroup1  //grouped by ip, computername, etc.

             ...pc0043

             ...pc0088

    Now, we would like to move computers pc0043 and pc0088 to our domain structure ALL\Superdomain.local\Country\City\Nondomain\

    Does it make sense?

    Not all computers are running on domain and we would like to keep them structured in a same way like domain machines. 

  8. Description: Possibility to change Dashboard for standard users

    Detail:

    Standard ESMC users (non admins) are not able to edit or adjust their dashboard configuration and they have to "stay" with the default template. Any change their made is not saved. 

    It would help a lot if they could re-configure dashboard with available predefined reports.

  9. Hello there, 

    I am trying to create a policy from requested client configuration. I was able to convert this configuration to a policy but it is not possible to change/disable some parts in it. For example I cannot disable some parts in "Real time & Machine learning protection", these reapear always enable.

    System details:

     

    ESET Security Management Center (Server), Version 7.2 (7.2.1266.0)
    ESET Security Management Center (Web Console), Version 7.2 (7.2.221.0)

     

    p.s. support ticket was created yesterday, but no feedback, yet. 

    2144553799_Changecannotbesaved.thumb.png.8d9eed765112bfbbe210310c9c36d89b.png

  10. On 7/20/2020 at 7:27 PM, MartinK said:

    Could you please provide more details, specially how you were able to resolve this issue? We have not encountered similar symptoms. Maybe there was full disk and it was not possible to use temporary tables due to insufficient disk storage? Or wrong encoding was used for temporary tables?

    Our tempDB was configured with a size limit and It looks like the last module update was the reason why tempDB has grown to it's maximum size.

    Everything is working fine after size limit of tempDB was increased.

  11. Has anyone experienced issues after last ESMC module updates?

    When update was finished, I was asked to reload the console. After doing that, error messages appeared in every "window" or dashboard. One hour later, ESMC console is just loading and loading.

    Any suggestions? Is there something still running in the background?

     

     

    Version details:

    ESET Security Management Center (Server), Version 7.2 (7.2.1266.0)
    ESET Security Management Center (Web Console), Version 7.2 (7.2.221.0)

     

    Update module1021 (20200218)

    Translation support module1805 (20200619)

    SysInspector module1278 (20200609)

    SSL module1048 (20200608)

    Push Notification Service module1064 (20200625)

    Configuration module1822.4 (20200505)

  12. On 04/01/2018 at 6:01 PM, foxbat77 said:

    Did not get the LiveGrid message on desktops before the update to 6.6.2068.0.    Most of my clients were running or or two versions behind, but they were already on Endpoint AntiVirus 6.6 at least.

     

    this is affecting all of my upgraded clients.  My RA shows 0 offline clients.

    I think that reporting about non working LiveGrid is new feature of 6.6 client. Eset LiveGrid need to have internet access. Check if required communication ports are open.

    Ports and addresses required to use your ESET product with a third-party firewall

  13. On 04/01/2018 at 10:09 PM, MichalJ said:
    • @Reports – there are limitation in how reports could be assembled, which are related to internal database structures, and how various tables are combined. It´s not possible to combine all of the tables together. However, there are improvements planned for the upcoming version of ESET Remote Administrator.

    This is a problem of DB design and it should be solved. It is also not possible to combine reports like in V5.

    @ Failed / Trace message  - some trace messages like "Task failed in the security product" are not telling us why this task failed. You should take more closer look on this.

    I will add also something:

    Description: LOG deletion uppon Computer deletion

    Detail: When I delete computer from ERA console, all coresponding logs in "Threats" are deleted too. This is a "no way" for security product.

  14. On 8. 6. 2017 at 10:14 AM, kapela86 said:

    I'm testing ESET Remote Administrator to deploy it in my company. I run into a stupid problem. In configuring polices, I want to ADD a network to list of known networks "Personal Firewall -> Known Networks". Right now users have their own lists on their computers and I DO NOT want to replace their whole list with list supplied by ERA (and in the end, block users from changing it). Is it possible?

    I am just curious why you want to do that?

    Isn't it more secure to set by default some company network as known network and anything else as public? Then you can build your FW rules base on this and still you can be sure that your rules are applied in correct network.

  15. Yes, you are right. Base on my tests, deactivated computer is still visible in "Lost & Found" group but without the "icons".

    For client activation you can create your own Activation task under Admin > Client Tasks. When creating new task choose "Client Activation" in TASK column.

    Edit: Additionaly to these icons, IP address is also not visible.

  16. 2 hours ago, HienKieu said:

    Hi Miami,

    In this case, the client was installed by all-in-one package installer, i tried with other package created from ERA again, but still got the same issue. I don't know what happened meanwhile the connection make sure that completely normal!

    Then I would try to uninstall Eset Client and then use Eset Uninstaller and use it for "cleaning" all client files. Agent would be still installed.

  17. 3 hours ago, HienKieu said:

    Hi all,

    I installed Eset File Security on Windows Server 2016 Standard from all-in-one package. After that, check out the Win Server 2016 console, has been fully installed.

    4.JPG.e8fa1c81fae6caeb469d0e5c58025937.JPG

    But, when i login ERA Webconsole, click on this computer -> Show Details -> Tab "Overview", i just only see component is "ERA Agent", NOT Product as picture below3.JPG.a787b95fdf86b001bd936501a60af633.JPG

    Make sure that the connection between Server-Agent is completely normal. I tried reboot, reinstall with other package all-in-one created from ERA Server (Appliance) but it still doesn't appear on this!

    Help me to explain and any solutions how to resolved it?

    Thanks in advance!

     

     

    I had similar issue which was caused when client was installed first and agent last. I didn't had time to play with that so I have uninstalled Agent and client and did new installation afterwards.

  18. I would suggest to check Agent logs first.

    C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs
    C:\Documents and Settings\All Users\Application Data\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs

  19. 6 hours ago, lasek101 said:

    Hello
    First problem

    I have computers in network with names starting with rpc15 rnb15 rfs15 ris15 etc

    I want create dynamic group which will contain only computers with names starting with rpc15 and rnb15, how can i do that?  
    Normally I would create query on computer name to show everything starting with rpc15 OR rnb15 - but with eset product I can't do that!!!!

    Secondary problem

    I have created dymanic group with query
    operator AND
    Device identifier, Identifier type   Equal         Computer name
    Device identifier, Identifier value  has mask    r??15*

    and after 24 hours nothing appeared in that group - waht is wrong?

    Try to use CONTAINS instead of MASK.

    Dynamic_group.png

    Edit: You can still use regular expressions. If you want use these, you need to change CONTAINS to REGEX.

  20. 19 hours ago, dennyx said:

    Hi,

    Please, could anyone help me with this issue to solve it? I don't want to set my endpoints in learning mode and rules would help me as much as you can imagine. :-) 

    Thank you.

    Create new firewall rule with following settings:

    - local ports: 53, 88, 123, 137, 138, 139, 389, 443, 445, 464, 636, 3268, 3269, 49153 - 65535

    - remote IP: all your AD servers ... if you have more of them

×
×
  • Create New...