ePO runs roundabout 2100 XP Clients and 700 Win-Server, organized by ip-adressrange.
Clients/Servers at branch sites are supported by 18 (UNC) repositories.
Several tasks are created at the organizational/group-level. (DAT Updates/ Engine-Updates / Patches / ODS and so forth). Works fine. Agent communicates/reports to the ePO Server only every 4 to 6h (due to performance issues)
Several “Clients”, over all “Groups”, do not have the VSE installed.
I can verify them by a report.
Can I create a “event driven installation task” and/or “report driven installation task” who first checks, if application (VSE) is NOT installed (like an report) and then starts the MSI install package.
It is not state of the art to create a task on organizational level with 2-300 agents, for only 5 to 10 missed VSE installations at that organization/group that activates unnecessarily a MSI installation, and causing a noticeable performance impact. Also it is obsolete to create for each “missed installation” an own task.
Task attached to TAGs could solve it, but ePO does not support this kind of configuration.
Or report attached for TAG criteria (eg. missing VSE)
any idea’s ?? documents????
*ePO 4.0 Patch 5
*McAfee Agent for Windows 4.0 Patch 3
*McAfee Agent for Windows 4.5 (eval)
*McAfee Agent for Linux 4.0
*McAfee Agent for Linux 4.5 (eval)
*VSE 8.0 (less than 50 Win2003-Server)
*VSE 8.5i (XP sp2 and Win2003 Server)
*VSE 8.7i (XP sp2 and Win2003 Server)
*GroupShield for Exchange 6.03
*HIP 7 (eval)
*Encrypted USB (eval)
*ePO 4.5 (waiting for Patch1)
*configured Agent will be distributed by ZENWorks (initial installation)
Essentially this is exactly what a task set to "run immediatly" accomplishes. When you define a deployment task and set the task to run immediatly the next time an agent communicates in picks this task up it will invoke it immeidatly. Upon invoking he deployment task the agent will connect to an available repository and download a detection script for every product you have confirgured the task to install (the detection scripts are small, typcially only a few kbs). The script is run and if it determines that the product is not installed the agent then downloads the install package for that product and launches the install.
It is important to note that tasks set to "run immediatly" will only run once on a client machine and will not run again unless the task has been changed in some way. To get a client machine to re-invoke a task simply make an arbitrary change to the task (such as disable it, save it, then re-enable it and save it) and the client machines will think the task has changed somehow and re-invoke the task on thier next ASCI.
I hope that helps!
First time I checked “run immediately” and as far as I could see, the msiexec.exe was launched; even
if the Apps already installed.
Therefore I never tried this option anymore. But I will verify your hint.
The target is the way to solve issues....
Thankx so far mas59.on 11/10/09 4:10 AM
After initiating a “run immediate install task” at the group/organization level all clients starts the script, even if it is not necessary.
The PCs are not the latest types. They are at least 4 to 5 years old.
The HelpDesk calls increased rapidly due to performance problems.
Due to this limitation, the best way, I guess, would be “verifying these clients by report (installed Products)” associates them to a TAG,
and run TAG attached Task only for those clients.
Generally the immediate run task would work, but due to cpu and/or memory limitations we need a workaround,
instead of running task at all clients, even if unnecessary.
Worth for FRM ??
The client machines by design will download and run the detection script as this is how they determine if the product should or should not be installed. If the detection script indicates the the specified product is already installed then the agent will not download the install package for the product or launch the install. If the detection script indicates the specified product is not already installed it will download the install package and launch the install.
If you are indicating the client machine is downloading and launching the install for VSE 8.7i for example but VSE 8.7i is already installed then this would indicate something is wrong with the VSE install on the client as the detections script is running and the results are indicating VSE is not installed when it really is.
As an alternative in EPO 4.5 you can schedule tasks based on tags. So here are the high-level steps you would take:
1- Create a report that lists all managed machines with no VSE (or the wrong version of VSE) installed
2- Create a tag for these machines
3- Automate the report you defined in step 1 so it runs daily (or hourly, whatever your preference) and the action on the report will be to assign the tag you defined in step 2
4- Create a deployment task at the appropriate level in EPO and in the "Description" tag select the "Has any of these tags" option and select the tag you assigned to these machines in step 3
5- Create a report that lists all managed machines which are reporting VSE as installed and that also have the tag you defined in step 2 applied to them
6- Automate the report you defined in step 5 so that is removes the tag you defined in step 2 from all machines on the report. This will prevent the machines from re-running the deployment task after they have successfully installed VSE
Its a bit complicated but it should work fine and I believe it will achieve your objective of only running the deployment task on machines that are not reporting VSE is installed.
now we are looking forward to migrate to epo 4.5 after launched epo4.5 SP1 and migrating Netshield to LinuxShield.
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center