Quantcast
Channel: Ivanti User Community : All Content - Endpoint Manager and Endpoint Security (EPM) (Powered by LANDESK)
Viewing all 1714 articles
Browse latest View live

Cancel Option

$
0
0

We just upgraded to 2018.3...... Now we get reports that Cancel option is not missing from any task that is running.   Is there a known bug? 


CSA - Failed to post the certificate to the CSA

$
0
0

Hi all,

 

I've followed the recommendations from here -

Error: "Failed to post the certificate to the CSA"

but none of the suggestions have worked.

 

We currently have this CSA attached to the old/current 9.6 core but trying to set it up on the new 2017.1 core and it won't add.

 

Here's what I've done.

 

Made a backup of the .0 file in ldlogon and then edited it to add CSA information as shown below.

Did the same for the .0 file in C:\Program Files\LANDesk\Shared Files\keys

1.jpg 

Time / date is ok

2.jpg

Network settings are ok, unchanged

3.jpg

 

Added new core 688944-uspldms2.ubm.net into Host Names

4.jpg
Added the new core IP address into the Security -> Allowed Addresses

5.jpg


Went to Configure -> Manage Cloud Services Appliances…  and entered the information as shown below and Apply

Getting this error from the core –

6.jpg

 

As said, I've also ran through the suggestions in the doc at the start of this, and the CSA is currently still working on the old core.

 

Any more ideas?  I've been tearing my hair out!

 

Cheers, Aaron


 

USMT Template and MigExclude Issues

$
0
0

I have been trying to get better control with what is copied over using the USMT template that was setup for us when first starting to use the End Point Manager. By "better control" I mean the following

 

     1. Exclude the Administrator and Public profiles from copying over

     2. Exclude certain program files from transferring from "C:" and "C:\Program Files (x86)"

 

My attempts to do this consist of the following

 

     1. Include this syntax in the "command line parameters" within the capture and restore templates

          /ue:*\* /ui:testuser

          /ue:*\Public /ue:*\Administrator /ui:testuser

 

          Note: Testuser is a domain account and imports properly. Also, I have tried many variations (inverting the /ui and /ue triggers etc.) on this type of syntax. I am also familiar with the notion "/uel" supersedes "/ui" supersedes "/ue"

 

     2.  I have included the following type of lines in the MigExclude.xml file within the USMT on our core server and it doesn't ever seem to make a difference. I look at the log and it continues to process items I enter exclusions for with the following format.

          <pattern type="File">C:\Program Files (x86)\K-Lite Codec Pack\* [*]</pattern>

          <pattern type="File">C:\Python27\* [*]</pattern>

          etc. etc. etc.

SWD LDMS 10 Download Error 105 (12)

$
0
0

Post converted to PDF and attached for Migration.

Unable to install Error WSCFG32.log

$
0
0

Post converted to PDF and attached for Migration.

Does anyone have a script to remove all Google chrome products and reset the Internet Explores back to default.

$
0
0

Post converted to PDF and attached for Migration.

LDMS 9.5 SP2

$
0
0

Hi,

I have upgraded from LDMS 9.0 SP2 to LDMS 9.5 SP2.

Below are some of the issues:

1. The AV doesnot install after an Agent Deployment.

2. Agent Status on some machine shows no connectiving to the machine in the concole, however i can ping or remote control the machine using the Inspect tool.

 

Please could anyone assist as I need to find a solution before I upgrade the Agents on the client machines.

IE11 No patches available

$
0
0

Post converted to PDF and attached for Migration.


Delete Agent Configuration while task is scheduled

$
0
0

Hello everyone,

 

I'm trying to delete an Agent from our Agent Configuration. It doesn't seem to work, the console says that there are several tasks in schedule...
I've deleted every scheduled task in "All tasks" but it still doesn't work.

 

Do you have any idea?

Can I remove the CBA_Anonymous account?

$
0
0

Issue:

A LANDesk administrator is questioning the necessity of the CBA_Anonymous account on client machines and is considering its removal.

 

What is it?

The CBA_Anonymous account is a local guest account created on any Windows computer that has a Landesk Agent. When your LDMS Core needs to communicate with an agent, it calls the CBA_Anonymous local account on the agent computer, to perform an LDPing on the client web service. The LDPing returns the hostname and Landesk inventory ID of the Agent computer as xml. This information is verified to authenticate the client before executing any task.

 

For more information, please click on the following link:

Landesk Agent Authentication using the CBA_Anonymous local guest account

 

Solution:

The removal of CBA_Anonymous has proven to exhibit various errors within various environments and may cause a fault in your services.

 

Please keep in mind that in versions 9.6 SP3 and later, the CBA_Anonymous account is no longer in the guest group, but is defaulted to the user's group. Please verify the version of your LANDesk agents if this is not the case.

 

For those machines 9.6 SP2 or earlier, the only known work around, which is unsupported, is to add CBA_Anonymous to the users group. You will however be required to ensure that the local policy "Deny Logon as Batch Job" does not contain the guests group. It can be found here:

Local Computer Policy>> Computer Configuration>> Windows Settings>> Security Settings>> User Rights Assignment

IEM 2017.3 SQL express error during install, which then leads to datamart error...

Capture UEFI W10 GPT very big size !

softmon.exe CPU utilization after 8.8 SP4

$
0
0

Hello,  I wander if anyone else has ran into this. After we upgraded our Core from 8.8 SP3 to SP4 and our clients ran security scans which triggered vulscan self update we've notices that on ALL clients softmon.exe jumped from 0 to 8 - 50 % CPU utilization. We finally figured out that it was related to Mcafee Virus Scan 8.7. Mcafee is a standard antivirus on our campus and installed on all of our client computers (yes, all 9000 of them!!!).

 

We tried to setup exclusions for all the LANDesk processes with no luck. At this point we are completely out of ideas. I should mention that I did open a case with tech support and they are looking into it. Meanwhile, we start taking more and more calls on this issue.

 

I was wandering if anyone else has seen this and perhaps has a solution or a work around.

 

Thanks in advance.

Landesk re-installation

$
0
0

Hello,

I just would like to know if there is any procedure or technical documentation on How to reinstall LANDESK ?

I am meeting here a crash of the OS and am not able to restore it so I decided to reinstall the OS and re-install Landesk.

My database is on another computer.

 

Could you help me?

 

Thanks a lot for your help.

 

Eric

2018.3 Portal Manager Logo publishing

$
0
0

Hey Folks!

 

I just wanted to drop this here for anyone else that may run into similar issues.  In a nutshell, uploading logos in portal manager would only sometimes sync to our clients...it typically resulted in a blank logo.  I know that the recommended file type is .png, but I haven't found any relevant information regarding file size (which doesn't matter, as I've discovered). 

 

Resolution:  If you pre-populate the logo on the core in x:\Ivanti\LdMain\landesk\files\SWDPolicyImages, *then* upload the logo image via distribution package (use the same name, file type) - you can safely trick the core into properly accepting the image, then syncing to the clients.  This issue was not seen in EPM 2017, it was just noticed in EPM 2018.3. 

 

Anyways, hope this helps someone out there!


Ivanti Antivirus (Bitdefender) EPM 2018.3

$
0
0

I would really love some help, we recently upgraded from 2017.3 to 2018.3 and we are using the BitDefender engine as AV, but while trying to configure the av within the agent, we got a message in red stating to download ivanti core installation files. we tried the steps but never got the option in the download for core installation files.

 

I then navigated to the AVclientBD folder and saw a updateserverinstall folder and tried to run the exe that was in the folder. can anyone guide us through is, i thought we would be able to just configure a new agent with bitdefender and go from there.

 

now i realize the av isnt installed on the new 2016 server we spun up for 2018.3. PLEASE HELP! below is a log from the update server folder and aslo two screenshots, one of the Core Installation message and one from Agent Settings showing there is now setting for Ivantio Antivirus 2017

 

14540 4 2018-11-28 16:14:14Z INFO ------------- Start Update Server intsall ---------------

14540 4 2018-11-28 16:14:14Z INFO Installing Update Server...

14540 4 2018-11-28 16:14:14Z INFO Renaming AVFilelist...

14540 4 2018-11-28 16:14:14Z INFO Successfully renamed 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\AVfilelist-New.txt' to 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\AVfilelist.txt'

14540 4 2018-11-28 16:14:14Z INFO Setup pkg path: C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\epsecurity_x64.exe

14540 4 2018-11-28 16:14:14Z INFO Updating install.xml for update server...

14540 4 2018-11-28 16:14:14Z INFO Successfully renamed 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\installer.xml' to 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\installer-client.xml'

14540 4 2018-11-28 16:14:14Z INFO Successfully copied 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\InstallerConfig.xml' to 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\installer.xml'

14540 4 2018-11-28 16:14:14Z ERROR install process exception:The system cannot find the file specified  ErrCode:0

14540 4 2018-11-28 16:14:14Z INFO Restoring client install.xml...

14540 4 2018-11-28 16:14:14Z INFO Successfully renamed 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\installer-client.xml' to 'C:\Program Files\LANDesk\ManagementSuite\ldlogon\AVClientBD\updateserverinstall\..\installer.xml'

14540 4 2018-11-28 16:14:14Z INFO Successfully installed update server

14540 4 2018-11-28 16:14:14Z WARN Failed to create shortcut.

LinkSource: ''

LinkDestDirectory: ''

LinkName: ''

14540 4 2018-11-28 16:14:14Z INFO Getting BD install path...

14540 4 2018-11-28 16:14:14Z ERROR can't find the registry key:SOFTWARE\Ivanti\Endpoint

14540 4 2018-11-28 16:14:14Z ERROR BD installDir is Empty, unable to set settings

14540 4 2018-11-28 16:14:14Z ERROR Failed to set settings

14540 1 2018-11-28 16:14:18Z INFO Checking for 'EPUpdateServer' service...

14540 1 2018-11-28 16:14:18Z INFO Didn't find 'EPUpdateServer' service

14540 1 2018-11-28 16:14:18Z INFO Checking for 'EPUpdateService' service...

14540 1 2018-11-28 16:14:18Z INFO Didn't find 'EPUpdateService' service

14540 1 2018-11-28 16:14:18Z INFO Checked for 2 services and found 0 services

14540 1 2018-11-28 16:14:18Z ERROR Installation failed.

Capture1.jpgCapture.jpg

Running Query of all Software Installed?

$
0
0

Has anyone figure out how to run a query of all the software installed on the computers they managed? I'd like to get a list of all software installed on each of the computers we have.

Discovery Data Mapping between Ivanti SM and EPM

$
0
0

Hello,

 

We have installed and are using

 

Ivanti Service Manager (2017.3.1000.31399 @ 3/15/2018)

 

We are also using EPM (Landesk discovery 10.1).

 

We are capturing Hardware IT Assets in the SM (as part of the COnfiguration Manager Role). We are also bringing in Discovery data on the assets eg RAM, OS, ETC. Under each record is a space to map the manually recorded asset with its related logical discovery data (ie RAM, OS, Serial Number, Model, etc of the hardware asset as discovered by the agent on the asset)  . Does anybody know what links the Discovery data to the asset record created manually in the Ivanti SM ?.

 

How does SM know what the OS , RAM of the manually record is ?. whats the unique identifier/ unique key that links the two ?. is it the PC name fields ( as PC name will be on the asset and also their is a field to record it manually in the config role of Ivanti SM ), or is it something else.

 

Thanks

How can I manage multiple sites in multiple countries?

$
0
0

Hi,

 

I have recently started managing many Ivanti EPM servers globally across many countries including places like UK, Brazil, Australia, UAE, India, South Africa and USA. I have just finished upgrading all servers to Ivanti EPM 2018.3 so they are all on the same software version. The servers are all configured different with different settings and strategies around security patching, software distribution, OS Provisioning, reporting/alerting, etc. Each country and office has it's own Ivanti EPM instance which do not currently communicate with each other.

 

I am looking to centralise, standardise and simplify everything. I am looking for advise on the best strategy of how to do this. I am currently researching into this to find all the options and then weigh up the options. In the UK I have a distribution point setup locally at one site as a test to see how this works but I am not sure this would be the best option globally when the Core server is in the UK as I imagine the replication would be slow. The other option is to have a rollup core which I don't know much about as yet but I am looking into. As far as I am aware a rollup core communicates with many different instances of Ivanti EPM and stores information from them all based on whatever criteria you set, this might be a better option as at least I could hopefully see what is happening on the servers from a central point. What I was really hoping for though is that I could have an Ivanti EPM core server in each site and they could do some sort of Core Synchronisation back to the Master Core server in the UK similar to a Master and a slave server. I would then make it so each onsite IT contact can only do things relating to clients in their office and things like security patching are completely standardised and the same across countries with exceptions where needed.

 

Does anyone know if this is possible from a technical point of view or have any ideas of how managing multiple countries can be made easy? I don't know if I am on the right track with the right line of thought or if there are other ways of doing what I want? I know there are other factors to consider like office politics and local laws of what information/data you can retain etc but that is less of an issue right now.

 

Any help is much appreciated and thank you in advance.

 

Kind regards,

Luke

Configure Ivanti Endpoint Manager web console to use https.

$
0
0

Is there any way to configure IEM web console to use https instead of http like Software License Monitoring (SLM)?

Viewing all 1714 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>