Endpoint Protection

 View Only
  • 1.  "Search for applications" missing a lot of common applications

    Posted Oct 10, 2012 03:18 PM

    Application learning is a favorite feature of mine, but it doesn't seem to be working properly:

     

    *Application learning is enabled under Clients/Communications Settings/"Upload" and Admin/Site Properties/General/"Keep track of every application..."

    *If I search for .exe's and .dll's common to c:\windows\system32\ on a Windows 7 machine I get no hits

    *Yet if I search for notepad.exe, I get results

     

    SEP Managers are 12.1.1101.401

    Most clients are 11.0.7101.1056

     

    I'm not finding anything about a known incompatibility between the two versions... any other ideas or troubleshooting steps?  This feature has worked really well in the past to find infections on multiple machines...



  • 2.  RE: "Search for applications" missing a lot of common applications

    Posted Oct 10, 2012 03:28 PM

    Have you seen the same issue when the client is at 12.1.1101.401 as well?



  • 3.  RE: "Search for applications" missing a lot of common applications

    Posted Oct 10, 2012 05:39 PM

    Upgrade a few clients to 12.1.1101.401 to see if that help



  • 4.  RE: "Search for applications" missing a lot of common applications

    Posted Oct 15, 2012 12:53 PM

    I've got a few clients on 12.1.671.4971 and common system files still do not appear.



  • 5.  RE: "Search for applications" missing a lot of common applications

    Posted Oct 15, 2012 01:59 PM

    To elaborate further:

    *The SEPM seems to learn of some applications, but not all of them.  For example notepad.exe produced plenty of results, but write.exe does not.

     

    I do have a support case going on this (an on the phone waiting right now in fact) but figured I'd throw this out there... One thing I'm wondering is, does SEP only "learn" about processes that actually run, or anything that lives in the machine?



  • 6.  RE: "Search for applications" missing a lot of common applications
    Best Answer

    Posted Oct 15, 2012 02:43 PM

    Should be for processes that actually run.



  • 7.  RE: "Search for applications" missing a lot of common applications

    Posted Oct 16, 2012 08:15 AM

    Ahh - that was one question I had (which the support engineer couldn't answer).  I'll make sure I run write and then check the database...

    Thanks!