PaulBO 0 Posted December 10, 2019 Share Posted December 10, 2019 Hi together. Now have a license for our company for more than 2 months but their product still does not work. Is really very unsatisfactory. First, the installation took a lot of time where I expected a docker-image. But well now the EraServer runs on a VM. There I built an installation agent (standard) and tried to install. We use more than 90% of Mac in our company but the ESMCAgent can not be installed. Here's the log: ESET Management Agent live installer script. Copyright © 1992-2019 ESET, spol. s r.o. - All rights reserved. * Hostname: eset.example.com * Port: 2222 * Installer: hxxp://repository.eset.com/v1/com/eset/apps/business/era/agent/v7/7.1.840.0/agent_macosx_x86_64.dmg Downloading installer image 'hxxp://repository.eset.com/v1/com/eset/apps/business/era/agent/v7/7.1.840.0/agent_macosx_x86_64.dmg': % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 42.3M 100 42.3M 0 0 28.5M 0 0:00:01 0:00:01 --:--:-- 28.5M Checking integrity of of downloaded package /tmp/EraAgentOnlineInstaller.dmg.V8g1sOc5: OK Mounting image '/tmp/EraAgentOnlineInstaller.dmg.V8g1sOc5': Prüfsumme für Protective Master Boot Record (MBR : 0) berechnen … Protective Master Boot Record (MBR :: Die überprüfte CRC32-Prüfsumme ist $F51392E7 Prüfsumme für GPT Header (Primary GPT Header : 1) berechnen … GPT Header (Primary GPT Header : 1): Die überprüfte CRC32-Prüfsumme ist $0CF46D0A Prüfsumme für GPT Partition Data (Primary GPT Table : 2) berechnen … GPT Partition Data (Primary GPT Tabl: Die überprüfte CRC32-Prüfsumme ist $28A6256F Prüfsumme für (Apple_Free : 3) berechnen … (Apple_Free : 3): Die überprüfte CRC32-Prüfsumme ist $00000000 Prüfsumme für disk image (Apple_HFS : 4) berechnen … ............................................................................................................................................... disk image (Apple_HFS : 4): Die überprüfte CRC32-Prüfsumme ist $B923934D Prüfsumme für (Apple_Free : 5) berechnen … (Apple_Free : 5): Die überprüfte CRC32-Prüfsumme ist $00000000 Prüfsumme für GPT Partition Data (Backup GPT Table : 6) berechnen … GPT Partition Data (Backup GPT Table: Die überprüfte CRC32-Prüfsumme ist $28A6256F Prüfsumme für GPT Header (Backup GPT Header : 7) berechnen … GPT Header (Backup GPT Header : 7): Die überprüfte CRC32-Prüfsumme ist $A31E4303 Die überprüfte CRC32-Prüfsumme ist $66FCA8EC /dev/disk3 GUID_partition_scheme /dev/disk3s1 Apple_HFS /private/tmp/EraAgentOnlineInstaller.mount.KLQUFbLx Installing package '/tmp/EraAgentOnlineInstaller.mount.KLQUFbLx/Agent-MacOSX-x86_64.pkg': installer: Package name is ESET Management Agent installer: Upgrading at base path / installer: The upgrade was successful. Cleaning up: "disk3" ejected. unlink: /tmp/postflight.plist: No such file or directory At the programs is now an "ESET Remote Administrator Agent" but this can not be started. Here is the output from "/Library/Application Support/com.eset.remoteadministrator.agent/Logs": 2019-12-10 11:20:30 Information: [Thread 0x116d08dc0]: Loading ESET modules from /Library/Application Support/com.eset.remoteadministrator.agent//Modules/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Local time is 2019-12-10 12:20:30 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProductLine: era 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProductVersion: 7.1.840.0 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: Locale: en_US 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProductInstanceID: f4197941-f90e-4d22-ae7e-61bc8ffb99b8 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProgramDataDirectory: /Library/Application Support/com.eset.remoteadministrator.agent// 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProductConfigurationDirectory: /Library/Application Support/com.eset.remoteadministrator.agent/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProgramLogsDirectory: /Library/Application Support/com.eset.remoteadministrator.agent//Logs/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: TempDirectory: /tmp/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProgramLibraryDirectory: /Applications/ESET Remote Administrator Agent.app//Contents/MacOS/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: ProgramEsetUpdatableModulesDirectory: /Library/Application Support/com.eset.remoteadministrator.agent//Modules/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: InstallConfiguration: CrashDumpsDirectory: /Library/Application Support/com.eset.remoteadministrator.agent//Dumps/ 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Hardware Fingerprint: 01009CB9-7B5E-AC18-71AB-2D7132373B3F 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loaded ESET modules: 1=1074,46=1041B,25=1053,40=1822 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Used memory before loaded module libraries is 31072 KB 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loading module library Updates 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Updates (used 588 KB) 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loading module library Symbols 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Symbols (used 432 KB) 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loading module library Database 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Database (used 532 KB) 2019-12-10 11:20:30 Information: Kernel [Thread 0x116d08dc0]: Loading module library Security 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Security (used 572 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library Scheduler 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Scheduler (used 516 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library NetworkGrpc 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library NetworkGrpc (used 644 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library Cleanup 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Cleanup (used 524 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library DataMiners 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library DataMiners (used 744 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library DynamicGroups 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loaded module library DynamicGroups (used 444 KB) 2019-12-10 11:20:31 Information: Kernel [Thread 0x116d08dc0]: Loading module library Replication 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Replication (used 532 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library Automation 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Automation (used 588 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library Users 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Users (used 436 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library Policies 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Policies (used 440 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library OSConnector 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library OSConnector (used 796 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library ESSConnector 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library ESSConnector (used 848 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library PushNotifications 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loaded module library PushNotifications (used 484 KB) 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library +EVSAConnector 2019-12-10 11:20:32 Warning: Kernel [Thread 0x116d08dc0]: Module library +EVSAConnector was not loaded 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library +ESLCConnector 2019-12-10 11:20:32 Warning: Kernel [Thread 0x116d08dc0]: Module library +ESLCConnector was not loaded 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library +EFSConnector 2019-12-10 11:20:32 Warning: Kernel [Thread 0x116d08dc0]: Module library +EFSConnector was not loaded 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library +EEAConnector 2019-12-10 11:20:32 Warning: Kernel [Thread 0x116d08dc0]: Module library +EEAConnector was not loaded 2019-12-10 11:20:32 Information: Kernel [Thread 0x116d08dc0]: Loading module library +ERAG1ClientConnector 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loaded module library +ERAG1ClientConnector (used 1324 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +MDMCoreConnector 2019-12-10 11:20:33 Warning: Kernel [Thread 0x116d08dc0]: Module library +MDMCoreConnector was not loaded 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +VAHCoreConnector 2019-12-10 11:20:33 Warning: Kernel [Thread 0x116d08dc0]: Module library +VAHCoreConnector was not loaded 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +ProxyConnector 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loaded module library +ProxyConnector (used 616 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +RDSensorConnector 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loaded module library +RDSensorConnector (used 600 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +EIAgentConnector 2019-12-10 11:20:33 Warning: Kernel [Thread 0x116d08dc0]: Module library +EIAgentConnector was not loaded 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library +EFDEConnector 2019-12-10 11:20:33 Warning: Kernel [Thread 0x116d08dc0]: Module library +EFDEConnector was not loaded 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loading module library Authentication 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Loaded module library Authentication (used 528 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Used memory before modules load and initialization is 43284 KB 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CUpdatesModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CUpdatesModule (used 112 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CSymbolsModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CSymbolsModule (used 1448 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CDatabaseModule 2019-12-10 11:20:33 Information: CDatabaseModule [Thread 0x116d08dc0]: Startup configuration builder builds successfully ... 2019-12-10 11:20:33 Information: CDatabaseModule [Thread 0x116d08dc0]: Startup connection pool created ... 2019-12-10 11:20:33 Information: CDatabaseModule [Thread 0x116d08dc0]: Builder rebuilds successfully ... 2019-12-10 11:20:33 Information: CDatabaseModule [Thread 0x116d08dc0]: Connection pool recreated ... 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CDatabaseModule (used 1940 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CAgentSecurityModule 2019-12-10 11:20:33 Information: CAgentSecurityModule [Thread 0x116d08dc0]: Initialized CertificationAuthorityManager with crypto library: "LibreSSL 2.2.7" 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CAgentSecurityModule (used 716 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module SchedulerModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module SchedulerModule (used 104 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CNetworkGrpcModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CNetworkGrpcModule (used 652 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CCleanupModule 2019-12-10 11:20:33 Information: CCleanupModule [Thread 0x116d08dc0]: Module initialized 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CCleanupModule (used 44 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CDataMinersModule 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x116d08dc0]: DataMinerCompletionHandler: Starting completion handler worker thread 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x116d08dc0]: DataMinerCompletionHandler: Starting completion handler worker thread 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x116d08dc0]: CStatusLogDataMiner: Initializing local status log cache 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x116d08dc0]: CStatusLogDataMiner: Finished initialization of status log cache 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CDataMinersModule (used 2764 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CDynamicGroupsModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CDynamicGroupsModule (used 76 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CReplicationModule 2019-12-10 11:20:33 Information: CReplicationModule [Thread 0x116d08dc0]: CReplicationModule: Initializing message processing 2019-12-10 11:20:33 Information: CReplicationModule [Thread 0x116d08dc0]: CReplicationModule: Module initialization done 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CReplicationModule (used 52 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module AutomationModule 2019-12-10 11:20:33 Information: AutomationModule [Thread 0x116d08dc0]: TaskResumeHandler: There are 0 pending task resume requests. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module AutomationModule (used 420 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CUsersModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CUsersModule (used 32 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CPoliciesModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CPoliciesModule (used 136 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CSystemConnectorModule 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x116d08dc0]: No installed ESET Product (EES) version was detected at start 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CSystemConnectorModule (used 120 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CEssConnectorModule 2019-12-10 11:20:33 Information: CEssConnectorModule [Thread 0x116d08dc0]: No trusted product daemon was found. 2019-12-10 11:20:33 Information: CEssConnectorModule [Thread 0x116d08dc0]: Connector was deactivated. No tasks will be processed and no logs will be produced. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CEssConnectorModule (used 60 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CPushNotificationsModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CPushNotificationsModule (used 56 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module ERAG1ClientConnector 2019-12-10 11:20:33 Information: ERAG1ClientConnector [Thread 0x116d08dc0]: <CONNECTOR_MODULE> exception N3Era10Connectors17G1ClientConnector20no_installed_productE occurred at /Users/eraautobuilds/workspace/ERA/release_7.1/397bd482/src/Products/RemoteAdministrator/Src/Connectors/ERAG1ClientConnector/Agent/ProductOfflineConfiguration/UnixProducts.cpp:170. Product not installed. 2019-12-10 11:20:33 Information: ERAG1ClientConnector [Thread 0x116d08dc0]: Connector was deactivated. No tasks will be processed and no logs will be produced. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module ERAG1ClientConnector (used 260 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module AgentToProxyConnectorModule 2019-12-10 11:20:33 Information: AgentToProxyConnectorModule [Thread 0x116d08dc0]: Connector was deactivated. No tasks will be processed and no logs will be produced. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module AgentToProxyConnectorModule (used 168 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module CRDSensorConnectorModule 2019-12-10 11:20:33 Information: CRDSensorConnectorModule [Thread 0x116d08dc0]: Connector was deactivated. No tasks will be processed and no logs will be produced. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module CRDSensorConnectorModule (used 184 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initializing module AuthenticationModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Initialized module AuthenticationModule (used 100 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Skipping crash dumps sending (disabled in configuration) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Used memory before modules start-up is 52772 KB 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CUpdatesModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CUpdatesModule (used 32 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CSymbolsModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CSymbolsModule (used 44 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CDatabaseModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CDatabaseModule (used 40 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CAgentSecurityModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CAgentSecurityModule (used 68 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module SchedulerModule 2019-12-10 11:20:33 Information: CAgentSecurityModule [Thread 0x700001915000]: Checking agent peer certificate expiration in 30 days 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterSleepEvent 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module SchedulerModule (used 72 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CNetworkGrpcModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CNetworkGrpcModule (used 68 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CCleanupModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CCleanupModule (used 92 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CDataMinersModule 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterTimeEvent 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterTimeEvent 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterTimeEvent 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterTimeEvent 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterTimeEvent 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x700001c27000]: Active threats were published 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterSleepEvent 2019-12-10 11:20:33 Information: CDataMinersModule [Thread 0x116d08dc0]: CExclusionHitsAgregatedDataminer: TimeEvent registered with RequestId=5. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CDataMinersModule (used 384 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CDynamicGroupsModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CDynamicGroupsModule (used 80 KB) 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Refreshing dynamic groups after replication 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CReplicationModule 2019-12-10 11:20:33 Information: CReplicationModule [Thread 0x116d08dc0]: CReplicationModule: Starting module 2019-12-10 11:20:33 Information: CReplicationModule [Thread 0x116d08dc0]: CAgentReplicationManager: Starting replication control messages processing 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Refreshing dynamic groups templates after replication 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CReplicationModule (used 72 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module AutomationModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module AutomationModule (used 64 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CUsersModule 2019-12-10 11:20:33 Information: AutomationModule [Thread 0x700001eb6000]: Facade: Loading all enabled triggers. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CUsersModule (used 88 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CPoliciesModule 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Refreshing static groups after replication 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CPoliciesModule (used 92 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CSystemConnectorModule 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Evaluating dynamic groups templates 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CSystemConnectorModule (used 20 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CEssConnectorModule 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: Connecting to product 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterSleepEvent 2019-12-10 11:20:33 Information: SchedulerModule [Thread 0x700001998000]: Received message: RegisterSleepEvent 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CEssConnectorModule (used 140 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CPushNotificationsModule 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: Connected to product, processing tasks 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: Retrieving general operating system information 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CPushNotificationsModule (used 276 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module ERAG1ClientConnector 2019-12-10 11:20:33 Information: AutomationModule [Thread 0x700001eb6000]: Facade: Trigger has been created [UUID=00000000-0000-0000-7006-00000000000a, TYPE=DYNAMIC_GROUP_JOINED, CONFIG=triggerType: DYNAMIC_GROUP_JOINED]. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module ERAG1ClientConnector (used 244 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module AgentToProxyConnectorModule 2019-12-10 11:20:33 Information: CPushNotificationsModule [Thread 0x700002145000]: Configuring EPNS with timeout = 10 sec and LicenseSeat = 'Default ERAAgent' 2019-12-10 11:20:33 Information: CPushNotificationsModule [Thread 0x700002145000]: EPNS Resource available => initializing Push Notification WakeUp handler 2019-12-10 11:20:33 Information: CPushNotificationsModule [Thread 0x700002145000]: PushNotificationWakeUp: registering with EPNS 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module AgentToProxyConnectorModule (used 232 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module CRDSensorConnectorModule 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module CRDSensorConnectorModule (used 224 KB) 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Starting module AuthenticationModule 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: StatusLog_OSINFORMATION_EDITION_STATUS: "Rows":[{"symbols":[{"symbol_type":374,"symbol_data":{"val_int":[1]}},{"symbol_type":368,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":375,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":377,"symbol_data":{"val_string":["Mac OS"]}},{"symbol_type":378,"symbol_data":{"val_string":["10.15.1"]}},{"symbol_type":379,"symbol_data":{"val_string":["macOS 10.15 (Catalina)"]}},{"symbol_type":381,"symbol_data":{"val_string":["64-bit"]}}]}] 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: StatusLog_OSINFORMATION_LOCALE_STATUS: "Rows":[{"symbols":[{"symbol_type":388,"symbol_data":{"val_int":[1]}},{"symbol_type":382,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":389,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":391,"symbol_data":{"val_string":["de_DE"]}}]}] 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: StatusLog_OSINFORMATION_TIMEZONE_STATUS: "Rows":[{"symbols":[{"symbol_type":399,"symbol_data":{"val_int":[1]}},{"symbol_type":393,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":400,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":402,"symbol_data":{"val_string":["CET"]}},{"symbol_type":403,"symbol_data":{"val_int":[60]}}]}] 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Started module AuthenticationModule (used 144 KB) 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Dynamic groups templates evaluation trace: Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000001" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000002" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Linux" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000003" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Mac OS" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is true Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000004" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_res_id: 301989891 val_res_id: 303104045 } symbol_id: 232 used_operator: OP_IN_EXACT }' and symbols [232,] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000005" } versionGuard: 1' with expression 'logicOperator: OR filters { operand { val_res_id: 301989909 } symbol_id: 232 used_operator: OP_EQUAL } filters { operand { val_res_id: 301989910 } symbol_id: 232 used_operator: OP_EQUAL } filters { operand { val_res_id: 301989911 } symbol_id: 232 used_operator: OP_EQUAL } filters { operand { val_res_id: 301989953 } symbol_id: 232 used_operator: OP_EQUAL }' and symbols [232,] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000006" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_res_id: 508906757892866567 } symbol_id: 466 used_operator: OP_EQUAL }' and symbols [466,] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000008" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_res_id: 508906757892866590 } symbol_id: 231 used_operator: OP_NOT_EQUAL }' and symbols [231,] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000009" } versionGuard: 1' with expression 'logicOperator: OR filters { operand { val_res_id: 301989908 } symbol_id: 232 used_operator: OP_EQUAL }' and symbols [232,] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000a" } versionGuard: 1' with expression 'logicOperator: OR filters { operand { val_string: "Android" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { val_string: "Android (Device Owner Mode)" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000b" } versionGuard: 1' with expression 'logicOperator: OR filters { operand { val_string: "iOS" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { val_string: "iOS DEP" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000c" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_int: 2 } symbol_id: 1874 used_operator: OP_IN_MASK }' and symbols [1874,val_int: 18014398509481984] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000d" } versionGuard: 1' with expression 'logicOperator: AND compositeFilters { logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { } symbol_id: 379 used_operator: OP_HAS_SUBSTRING negation_operand { val_string: "Server" } } } compositeFilters { logicOperator: AND filters { operand { val_int: 8 } symbol_id: 1874 used_operator: OP_IN_MASK } }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"][1874,val_int: 18014398509481984] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000e" } versionGuard: 1' with expression 'logicOperator: AND compositeFilters { logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { } symbol_id: 379 used_operator: OP_HAS_SUBSTRING negation_operand { val_string: "Server" } } } compositeFilters { logicOperator: AND filters { operand { } symbol_id: 1874 used_operator: OP_IN_MASK negation_operand { val_int: 8 } } }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"][1874,val_int: 18014398509481984] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-00000000000f" } versionGuard: 1' with expression 'logicOperator: AND compositeFilters { logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { val_string: "Server" } symbol_id: 379 used_operator: OP_HAS_SUBSTRING } } compositeFilters { logicOperator: AND filters { operand { val_int: 8 } symbol_id: 1874 used_operator: OP_IN_MASK } }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"][1874,val_int: 18014398509481984] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000010" } versionGuard: 1' with expression 'logicOperator: AND compositeFilters { logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { val_string: "Server" } symbol_id: 379 used_operator: OP_HAS_SUBSTRING } } compositeFilters { logicOperator: AND filters { operand { } symbol_id: 1874 used_operator: OP_IN_MASK negation_operand { val_int: 8 } } }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"][1874,val_int: 18014398509481984] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000011" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { } symbol_id: 379 used_operator: OP_HAS_SUBSTRING negation_operand { val_string: "Server" } }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000012" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Microsoft Windows" } symbol_id: 377 used_operator: OP_EQUAL } filters { operand { val_string: "Server" } symbol_id: 379 used_operator: OP_HAS_SUBSTRING }' and symbols [377,val_string: "Mac OS"][379,val_string: "macOS 10.15 (Catalina)"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000013" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "iOS DEP" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000014" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { val_string: "Android (Device Owner Mode)" } symbol_id: 377 used_operator: OP_EQUAL }' and symbols [377,val_string: "Mac OS"] is false Dynamic group template 'uuid { uuid: "00000000-0000-0000-7014-000000000015" } versionGuard: 1' with expression 'logicOperator: AND filters { operand { } symbol_id: 1874 used_operator: OP_IN_MASK negation_operand { val_int: 983055 } }' and symbols [1874,val_int: 18014398509481984] is true 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: StatusLog_DEVICEINFORMATION_DEVICE_STATUS: "Rows":[{"symbols":[{"symbol_type":139,"symbol_data":{"val_int":[1]}},{"symbol_type":133,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":140,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":142,"symbol_data":{"val_string":["Apple Inc."]}},{"symbol_type":143,"symbol_data":{"val_string":["MacBookPro13,3"]}},{"symbol_type":4017,"symbol_data":{"val_string":["C02SX3P2GTFM"]}}]}] 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Agent is matching 2 dynamic group templates from 20 2019-12-10 11:20:33 Information: CDynamicGroupsModule [Thread 0x700001d2d000]: Agent is matching dynamic group template 'Operating system is Mac OS' with uuid 00000000-0000-0000-7014-000000000003 and version 1 2019-12-10 11:20:33 Information: CSystemConnectorModule [Thread 0x70000203f000]: StatusLog_IDENTIFIERS_LIST_STATUS: "Rows":[{"symbols":[{"symbol_type":271,"symbol_data":{"val_int":[1]}},{"symbol_type":265,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":272,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":274,"symbol_data":{"val_res_id":[508906757892866566]}},{"symbol_type":275,"symbol_data":{"val_string":["Paul-MacMaster.fritz.box"]}}]},{"symbols":[{"symbol_type":271,"symbol_data":{"val_int":[1]}},{"symbol_type":265,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":272,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":274,"symbol_data":{"val_res_id":[508906757892866565]}},{"symbol_type":275,"symbol_data":{"val_string":["Paul-MacMaster"]}}]},{"symbols":[{"symbol_type":271,"symbol_data":{"val_int":[1]}},{"symbol_type":265,"symbol_data":{"val_uuid":[{"uuid":"f4197941-f90e-4d22-ae7e-61bc8ffb99b8"}]}},{"symbol_type":272,"symbol_data":{"val_time_date":[{"year":2019,"month":12,"day":10,"hour":11,"minute":20,"second":33}]}},{"symbol_type":274,"symbol_data":{"val_res_id":[508906757892866564]}},{"symbol_type":275,"symbol_data":{"val_string":["C02SX3P2GTFM"]}}]}] 2019-12-10 11:20:33 Information: AutomationModule [Thread 0x700001eb6000]: SimpleSchedulerTriggerBase: Trigger [UUID=00000000-0000-0000-7006-000000000001, TYPE=REPLICATION] registering scheduler event [StartTime { year: 2019 month: 12 day: 10 hour: 11 minute: 20 second: 33 } TimeSpecification: "R R/1 * * * ? *" UTCLocal: true]. 2019-12-10 11:20:33 Information: Kernel [Thread 0x116d08dc0]: Used memory after modules start-up is 55248 KB And also here is the output from Status.log html: Is there a solution to the problem? I do not really want to go to any of our Mac's and do something manually. Link to comment Share on other sites More sharing options...
ESET Staff MichalJ 434 Posted December 10, 2019 ESET Staff Share Posted December 10, 2019 Hello, I am not completely sure I did understand your post, but what is the actual problem? Based on the status log, your agent is successfully connecting, it even replicates some matching dynamic groups. Also, the install log shows, that upgrade was performed successfully, meaning there was previously some other version of ESMC / ERA agent installed. When you mention docker image, you talk about ESMC server? We do not provide docker image, just an OVA, that you can import inside your virutalized environments. You are free to call our technical support, that should be able to asist you with your questions / problems. Regards, Michal Link to comment Share on other sites More sharing options...
Recommended Posts