3 Replies Latest reply on May 26, 2016 2:14 PM by sw41

    Big problem with ePO 5.3 (on-prem) and ENS 10.1.1

    mplb

      Since upgrading our ENS clients to 10.1.1 (Patch 1) our ePO is unable to process any threat events that it receives from the clients and the ePO dashboards are now pretty much useless.

       

      McAfee are investigating but it's now been almost 5 days and it's still not resolved.

       

      We're running the on-premise ePO version 5.3 with the latest patch(es) applied and the agent version running is 5.0.2.132. The kinds of errors we are seeing are:

       

      masvc(1672.1688) event.Error: Failed to move file from C:\ProgramData\McAfee\Agent\\AgentEvents\20160523210121150437500000ED0.txml to C:\ProgramData\McAfee\Agent\\AgentEvents\Upload\mc_20160523210121150437500000ED 0.txml

       

      Is anyone else experiencing this problem or are we unlucky and alone?

        • 1. Re: Big problem with ePO 5.3 (on-prem) and ENS 10.1.1
          twenden

          I feel your frustration as support took a long time to solve our issue with ENS 10.1. We had an issue where events would not display in the ePO console. We discovered this during testing as any virus events, using the test eicar virus, would not show up on the dashboard. McAfee tech support referred us to KB86071 which is titled "ePolicy Orchestrator console fails to display point product events and an error appears in the eventparser.log" . It refers to ENS 10.1 and is fixed by fixing the ePO database user. Not too sure if you have the same issue or not.

          • 2. Re: Big problem with ePO 5.3 (on-prem) and ENS 10.1.1
            mplb

            Thanks for this info but I don't think it's the same issue. Events from ENS 10.1.0.x clients get processed by the ePO, it's just events from the new ENS 10.1.1.x that seem to be confusing the ePO.

             

            The clients seem to be detecting and dealing with the threats but whatever is being sent back to the ePO from 10.1.1.x clients is unable to get copied to the correct location for processing. The queue is somewhat large after almost 5 days of knackeredness.

             

            Very unimpressed so far with the support from McAfee on this and, as usual, Sod's Law seems to be in action that we are the only organization in the world to be suffering from this issue.

            • 3. Re: Big problem with ePO 5.3 (on-prem) and ENS 10.1.1
              sw41

              We are 5.3 on prem as well and have had better luck with our users on Agent 5.0.2.333 and were told that was a pre-req to having ENS.  Our events are processing but all of my queries for ENS related stuff are slow to some up.  We have a small install with 2k end points so would be scared to see how slow they took with larger sites.  Sorry we could not un-Sod your issue.