When using the "Collect Remote Diagnostic Logs" option within SES Cloud to request logs from a SEP client you see the request show "In Progress" and later "Failed" from Command Status.
Also from the the relevant SEP client's activity history pane you also see the following events:
- Command 'Collect Remote Diagnostic Log started'
- Command 'Collect Remote Diagnostic Log' will be retried later (error: 0x80040300).
NOTE:
Category: 3-Application Activity
Event Type ID: 11-Command Activity
Symantec Endpoint Security (SES)
This error is displayed when the SEP client is "missing" Remote Diagnostics (RSDDefs) definitions.
To resolve this issue, perform one of the following actions:
1. Run LiveUpdate to download the latest Remote Diagnostics definition set (RSDDefs)
Example System Log:
6/8/2026 11:03:26 AM 302450688 2 None "An update for Remote Diagnostics Win64 from LiveUpdate was successfully installed. The new sequence number is 250110001.
2. Reinstall the SEP client to ensure all definition sets are correctly initialized
NOTE: If using Live Update Administrator (LUA), make sure to include the following "content" within your relevant Download, Distribution and Distribution Center schedules for your SEP versions:
Content Updates:
- Remote Diagnostics
- Remote Diagnostics ARM 64 (if applicable)
CRE-24125