Scan report from ICDM console shows blank data for Endpoint Security clients.
search cancel

Scan report from ICDM console shows blank data for Endpoint Security clients.

book

Article ID: 371604

calendar_today

Updated On:

Products

Endpoint Security Complete

Issue/Introduction

Endpoint clients were connected and managed by SEPM and then migrated to connect to ICDM/ SES console directly.

The scan data displayed in scan report on ICDM is blank for all the clients.

Environment

SES 14.3.x clients

Cause

Before client migration, Virus and Spyware policy set in SEPM had 'Log Handling' setting for scan events sent to management server as unselected.

Resolution

For now, there is no option on ICDM console to change the scan events log settings on clients to be forwarded to ICDM console if they were unchecked before migration.

 

Try the following options in such scenario.

1. Modify the Registry on clients manually or using 3rd party tools:

HKLM\software\symantec\symantec endpoint protection\av\common\forwardevents\0 

Keys:  2,3,21,26,27,65,66,67,69

Value: 1

 

2. Modify the Registry using Compliance Policy (HI policy) available on ICDM console for all the affected clients..

On ICDM console navigate to Policies >>  Compliance policy

Under Requirements, Click ADD
Type Requirement Name
Under Custom Requirement Script click ADD - Select Function
Under Function, Select Registry: Set registry value

Registry Key :  HKLM\software\symantec\symantec endpoint protection\av\common\forwardevents\0
Value Name: 2
Value Type: Dword Value
Value Data:1

Repeat the above steps and add the function for 'Registry: Set registry value' for remaining Value Name: 3,21,26,27,65,66,67,69

Select the result of requirement as Pass. (Screenshot below)

Assign the policy to groups and confirm that the configured registry is modified on the clients.

3. Uninstall and Reinstall SEP clients.