cancel
Showing results for 
Search instead for 
Did you mean: 

VSE 8.8.0.1445 (P6) - Threat events not parsing?


Just updated extensions and packages to the most recent RTW extensions and packages for VSE and noticed two things during tests.

EICAR file detection only alerted once, though if I had repeated the same download VSE had identified it and sent it to quarantine multiple times, the notification window only displayed once; not critical, but an issue.

More important; threat events are now no longer parsing in ePO, all threat events (including the 3 for the above EICAR test) are going into debug folder.

Environment:

ePO:                          5.1.1.357

VSE:                          8.8.0.1445 (P6) RTW

VSE Extensions:     

          VirusScan Enterprise 8.8:          8.8.0.412

          VirusScan Enterprise Reports:  1.2.0.263

Engine:                     5700.7163

DAT:                         7906

Anyone else experience this issue?

5 Replies

Re: VSE 8.8.0.1445 (P6) - Threat events not parsing?

UPDATE:  Issue one is not observed on same test file with VSE 8.8.0.1385 (P5), each detection is alerted as it used to.

However issue two persists, Threat events are no longer parsing (from any VSE version endpoint) now that the updated extensions are checked into ePO.

Re: VSE 8.8.0.1445 (P6) - Threat events not parsing?

Good - its not just my EPO server then.....haha.

I have restarted, removed and re-added the report extension from EPO software manager, etc.

Same problem, no threats showing - they are all showing the debug folder, yet everything is installed correctly.

Another Patch 5 rollout failure into Patch 6?

Re: VSE 8.8.0.1445 (P6) - Threat events not parsing?

Looks like they know its an issue now - how in the world it got past testing I will never know.

Work around is to install previous extension.

https://kc.mcafee.com/corporate/index?page=content&id=KB84854

Pmaquoi
Level 11
Report Inappropriate Content
Message 5 of 6

Re: VSE 8.8.0.1445 (P6) - Threat events not parsing?

as the kb explain it, the P5 report extension with the P6 management extension seems to work on one of my ePO.

Troja
Level 14
Report Inappropriate Content
Message 6 of 6

Re: VSE 8.8.0.1445 (P6) - Threat events not parsing?

Hi all,

my coworker figured out the same problem. Removed the Reporting extension from Patch 6 and installed the Extension from Patch 5.

PLEASE MCAFEE, how can this happen. How about the Quality Management. Such a problem must been detected!!!!!!

Cheers