Monday, April 6, 2009

TMCM 3.5 security logs

Concern
+++++++++
Hello, I have customer asking me why at his TMCM, he can see the result for unsuccessful entry. Whereas, when he digged the OSCE log for the day there was nothing related being found, Further looking at the TMCM log, it is found that the time the log was generated at entity was back 8 months. Whereas the time received from entity show yesterday date. My question is why it is taking long time for the OSCE to send the logs to TMCM? Please explain in what condition that this things happen. How to remedy. I will attach together tmcm and officescan log for yesterday. If you look at the Tmcm log, look at the first and second column. Some are of the same day differs only 1 hour which is acceptable. but some are few months different. Should you need more info, please let me know.

Suggested solution
+++++++++++++++++++++
"Generated at entity" means that the information log was generated at the OfficeScan. "Received from entity" means the the information log was received by Control Manager. From the log, it showed that OfficeScan generated the log on 6/9/2008 and was uploaded to Control Manager on 2/4/2009. There are several reasons for this kind of issue. Below are the possible reason:

1. TMCM purged already the logs (depending on Purge settings) but the particular log is still on OfficeScan.
2. The log was queued on OfficeScan.
3. OfficeScan was offline during that time.

We can adjust the polling of logs from Agent.ini file. Agent.ini normally located in ..OfficeScan\PCCSRV\CmAgent\

More details on parameter to edit, I'd recommend you submit to Trend Portal. Anyway the number indicated in agent.ini is in seconds.

1 comment:

Sha said...

Jennifer: Thanks Jennifer!