Endpoint clients were connected and managed by SEPM and then migrated to connect to ICDM/ SES console directly.
The scan data displayed in scan report on ICDM is blank for all the clients.
SES 14.3.x clients
Before client migration, Virus and Spyware policy set in SEPM had 'Log Handling' setting for scan events sent to management server as unselected.
For now, there is no option on ICDM console to change the scan events log settings on clients to be forwarded to ICDM console if they were unchecked before migration.
Try the following options in such scenario.
1. Modify the Registry on clients manually or using 3rd party tools:
HKLM\software\symantec\symantec endpoint protection\av\common\forwardevents\0
Keys: 2,3,21,26,27,65,66,67,69
Value: 1
2. Modify the Registry using Compliance Policy (HI policy) available on ICDM console for all the affected clients..
On ICDM console navigate to Policies >> Compliance policy
Under Requirements, Click ADD
Type Requirement Name
Under Custom Requirement Script click ADD - Select Function
Under Function, Select Registry: Set registry value
Registry Key : HKLM\software\symantec\symantec endpoint protection\av\common\forwardevents\0
Value Name: 2
Value Type: Dword Value
Value Data:1
Repeat the above steps and add the function for 'Registry: Set registry value' for remaining Value Name: 3,21,26,27,65,66,67,69
Select the result of requirement as Pass. (Screenshot below)
Assign the policy to groups and confirm that the configured registry is modified on the clients.
3. Uninstall and Reinstall SEP clients.