9 Replies Latest reply on May 23, 2011 7:48 PM by whookie

    How often are virus pattern updates published by LANDesk?

    Apprentice

      We recognized, that there is only once or twice a day new antivirus pattern updates downloaded to our core. We scheduled an 1 hour update interval for downloads.

      I could not found any official statement about the regular publishing interval of new antivirus pattern updates.

      So how often is that happen at a normal day? Once, twice, every four hours a day?

       

      Is there any official landesk site with a list of all published patterns and the publishing date? So that users could verify that everything runs well?

       

      Thanks for help

      Nils

        • 1. Re: How often are virus pattern updates published by LANDesk?
          LANDave SupportEmployee

          As you are likely aware, LANDesk Antivirus uses the Kaspersky Antivirus engine.    The pattern files are downloaded from Kaspersky.

           

          The following Kaspersky website contains pattern release information, etc.

           

          http://www.kaspersky.com/viruswatch3

          • 2. Re: How often are virus pattern updates published by LANDesk?
            Apprentice

            On the kaspersky website they list four releases after 04:00h (at  05:42, 08:41, 12:22 and 15:10).

            Although our core did not receive new  patterns, when the update download task runs at 16:00h, 15:00, 14:00, and so on. For example we received the last pattern update at 04:06h  today (11.5.11).

             

            I wonder why our schechuled task running every hour just downloads new patterns every four to six hours, althoug there a much more releases by kaspersky.

             

            From what I see in the logs from the download taks on the core downloads pattern files from patch.landesk.com and not directly from kaspersky ( path: core-host\LDlog\vaminer.log).

             

            Could you give me a hint, where i can check the right download log for pattern download from kaspersky.

            • 3. Re: How often are virus pattern updates published by LANDesk?
              LANDave SupportEmployee

              What version of LANDesk Antivirus are you on?

               

              VAMINER.LOG is the correct log file to look at for the download activity.

              • 4. Re: How often are virus pattern updates published by LANDesk?
                Apprentice

                We are on version 9.0.2.3 Patchlevel LD90-SP2-MCP_CORE-2011-0324

                • 5. Re: How often are virus pattern updates published by LANDesk?
                  Apprentice

                  just guessing:

                   

                  there might be a credential problem in reading the kaspersky download location out of configuration. Instead of direct download using patchemea.landeks.com as fallback?

                   

                  Our Log for \vaminer.details.log:

                   

                   

                  05/09/2011 10:00:03 INFO  3860:1     :  -------------------------------------VAMiner Started.   --------------------------------------
                  05/09/2011 10:00:03 INFO  3860:1     : Commandline arguments:
                  05/09/2011 10:00:03 INFO  3860:1     :        /TASKID=1336
                  05/09/2011 10:00:04 INFO  3860:1     : Current language: DEU
                  05/09/2011 10:00:04 INFO  3860:1     : Using culture info: de-DE
                  05/09/2011 10:00:04 INFO  3860:1     : Error: Unable to find user 'OURDOMAIN\SYSTEM' in the ConsoleUser table.
                  05/09/2011 10:00:12 INFO  3860:1     : ------------------- Update process started --------------------
                  05/09/2011 10:00:12 INFO  3860:LoadingPatchSources : Error: Unable to find user 'OURDOMAIN\SYSTEM' in the ConsoleUser table.
                  05/09/2011 10:00:18 INFO  3860:1     : Zugriff auf Site Europa wird geprüft (https://patchemea.landesk.com)

                  • 6. Re: How often are virus pattern updates published by LANDesk?
                    LANDave SupportEmployee

                    Sorry,

                     

                    There is another log that gives the details for the actual pattern file download process, I had forgotten to mention it.

                     

                    \Program Files (x86)\landesk\ManagementSuite\log\GetBases.exe.log

                     

                    There should be a line in there that says "Set to download from Kaspersky site" if it is downloading from Kaspersky.

                    • 7. Re: Obviously the user of landesk antivirus do not get all regular updates
                      Apprentice

                      ok

                       

                      in the log  GetBases.exe.log

                       

                      there is  a line in there that says "Set to download from Kaspersky site".

                       

                       

                       

                       

                      But in the log there is no update for hours, thats strange compared to the official kaspersky site (http://www.kaspersky.com/viruswatch3) saying there were three  regular releases published at 12:22h; 15:10 and 17:22.

                       

                      kaspersky_releases_11052011_1810.png

                       

                      Why is there such a lag in time before an update is processed in landesk? Obviously the user of landesk antivirus do not get all regular updates in the moment.

                       

                       

                      ManagementSuite\log\GetBases.exe.log:

                       

                      Wed, 11 May 2011 11:01:10 All files are up-to-date.(10)

                      Wed, 11 May 2011 12:01:11 All files are up-to-date.(10)

                      Wed, 11 May 2011 13:00:56 All files are up-to-date.(10)

                      Wed, 11 May 2011 14:00:49 All files are up-to-date.(10)

                      Wed, 11 May 2011 15:00:53 All files are up-to-date.(10)

                      Wed, 11 May 2011 16:02:20 All files are up-to-date.(10)

                      Wed, 11 May 2011 17:01:15 All files are up-to-date.(10)

                      Wed, 11 May 2011 18:01:45 All files are up-to-date.(10)

                      • 8. Re: How often are virus pattern updates published by LANDesk?
                        Expert

                        We are working with kaspersky to determine why there is a difference in the times shown.

                        • 9. Re: Obviously the user of landesk antivirus do not get all regular updates
                          Expert

                          I am unable to talk specifically to the Getbases log, but in terms of how the Viruswatch times work. Here is what Kaspersky has told us.

                           

                          The Viruswatch website time are in in Moscow local time. They do not adjust to the timezone of the local Computer.

                           

                          The times that are shown in the Landesk Console are in GMT.

                           

                          There will be a difference in minutes because there is a verification process that the pattern files goes through before they are made public. The Viruswatch website does not adjust for that process.

                          1 of 1 people found this helpful