I recently started to monitor the DLP status on the Enterprise ePO server that I am adminstering. When I brought up the query for DLP Agent Status I am showing that over 50% of the workstations have this status:
"Agent is not running - user is logged off"
I remotely logged into one of the workstations and verified that the DLP Agent was running and it was and even the pop up showing that it operating when you first logged in appeared.
So I am stumped... Why is the agent status reporting this?
Any information would be greatly appreciated.
1. Usually a pending reboot on clients cause this.
2.Send an agent wakup calls to all these machines and run this query again.
Since I can't do a wake up agent from the DLP: Agent Status query, I went to a different query that allowed me to send an agent wakeup call.
I am waiting to see if there are any changes and will let you know.
next day check and only a few of the workstations have changed the status. I will have to work with others to possibly
request a reboot of all systems that have the problem.
Yes reboot will fix it. If you are ePO admin then select all your machine under system tree with a single check box at the upper bar and then at the bottom click Wake agent. Could you wakeup McAfee agents on clients in this way or if you already have don it then Reboot is required.
What you just suggested I tried with some a portion of the systems. I did a Wake Agent and only a few changed status.
I will be working with the system administrators to clear this issue.
Thank you for your suggestion.
Just tried another workstation doing an agent wake-up call.
I checked off force policy update (force complete policy and task update)
I also change the number of attempts to 2 to make sure. It is now over 15 minutes
later and the system is still showing the last CLP to ePO communication was on 20
June. The McAfee agent has communicated today without issue.
Thank you again,
can you browse that machine from ePo
http:// machine ip:8081 or can you see agent logs under system tree>Action>Agent>Show agent log? can you confirm the ASCI from this log?
can you telnet this macine on these ports
8081 80 and 443
I am restricted from attempting to do your suggestions due to the security posture of the network.
I am contacting McAfee directly for assistance.
Thank you for trying to assist me in solving this issue as it is much appreciated.