<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Zaheer, in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056930#M1142</link>
    <description>&lt;P&gt;Hello Zaheer,&lt;/P&gt;
&lt;P&gt;Just enable the DEBUG and let it run for 15-20 minutes and generate the diagnostics file.&lt;/P&gt;
&lt;P&gt;Enabling the DEBUG wont affect the system.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Jul 2017 14:49:33 GMT</pubDate>
    <dc:creator>Jetsy Mathew</dc:creator>
    <dc:date>2017-07-09T14:49:33Z</dc:date>
    <item>
      <title>AMP for Endpoint auto scan</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056925#M1071</link>
      <description>&lt;P&gt;I have been working on AMP for network and Endpoints, at start I faced a lot of issues with servers which i gradually resolved with addition of exclusions but for the last few days I dont know how and why AMP connector starts scanning the endpoint and effects performance of the machine.&lt;BR /&gt;can anyone help me on this please.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Looking forward.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056925#M1071</guid>
      <dc:creator>zaheer.jahangir1</dc:creator>
      <dc:date>2020-02-21T05:04:33Z</dc:date>
    </item>
    <item>
      <title>What kind of scan it is?</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056926#M1098</link>
      <description>&lt;P&gt;What kind of scan it is? Automatic scan you've configured in policy? if yes, is it full or flash or custom scan? When you say it affects the performance, you mean CPU or Disk activity goes high? It crashes the system?&lt;/P&gt;
&lt;P&gt;Verify the scheduled scan by editing the policy:&amp;nbsp;File &amp;gt; Scheduled Scans&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B class="MenuOption"&gt;Full&lt;/B&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;scan will scan the processes running, the registry entries, and all the files on disk. This scan is very resource-intensive and should not be performed on a regular basis. So avoid full scan every time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;There is another scan by policy, verify if you've this configured:&lt;/P&gt;
&lt;P&gt;https://console.amp.cisco.com/help/en/wwhelp/wwhimpl/js/html/wwhelp.htm&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you open up a TAC case with diagnostic file attached, that would be great.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056926#M1098</guid>
      <dc:creator>Dinesh Verma</dc:creator>
      <dc:date>2017-07-05T21:11:52Z</dc:date>
    </item>
    <item>
      <title>well the memory gives spikes.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056927#M1109</link>
      <description>&lt;P&gt;well the memory gives spikes...can i check what are the files and paths etc that are currently being checked by AMP, I mean those files folders that will not be a part of exclusions.&lt;BR /&gt;are these all running services, if yes then do we have to exclude all these running services, if yes then it is weird.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 11:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056927#M1109</guid>
      <dc:creator>zaheer.jahangir1</dc:creator>
      <dc:date>2017-07-09T11:08:52Z</dc:date>
    </item>
    <item>
      <title>Hello Zaheer,</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056928#M1126</link>
      <description>&lt;P&gt;Hello Zaheer,&lt;/P&gt;
&lt;P&gt;If you are seeing the memory spikes, then we need the diagnostics file . if its a version 5.1 , then you wont be be able to get the file counts and path which is continoulsy scanned by AMP by using the sqlite queries. if the version is below 5.1 then you can use the following article to run the sql query and get the list of files that are scanned.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/advanced-malware-protection-endpoints/118802-technote-fireamp-00.html&lt;/P&gt;
&lt;P&gt;if you are using the version above 5 or 5.1 , then please open a TAC case and get the diagnostics in DEBUG mode so that team can help you in the fine tuning.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rate if this answer helps.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 11:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056928#M1126</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-09T11:21:57Z</dc:date>
    </item>
    <item>
      <title>Hi Jetsy,</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056929#M1135</link>
      <description>&lt;P&gt;Hi Jetsy,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Putting it in debug mode will not further effect the system?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 11:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056929#M1135</guid>
      <dc:creator>zaheer.jahangir1</dc:creator>
      <dc:date>2017-07-09T11:30:40Z</dc:date>
    </item>
    <item>
      <title>Hello Zaheer,</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056930#M1142</link>
      <description>&lt;P&gt;Hello Zaheer,&lt;/P&gt;
&lt;P&gt;Just enable the DEBUG and let it run for 15-20 minutes and generate the diagnostics file.&lt;/P&gt;
&lt;P&gt;Enabling the DEBUG wont affect the system.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 14:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056930#M1142</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-09T14:49:33Z</dc:date>
    </item>
    <item>
      <title>This debug must go to Cisco</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056931#M1152</link>
      <description>&lt;P&gt;This debug must go to Cisco or is the debug something like routers/switches and Firewalls which we can also have a look at or is there any special tool used for this by cisco.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 05:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056931#M1152</guid>
      <dc:creator>zaheer.jahangir1</dc:creator>
      <dc:date>2017-07-10T05:23:14Z</dc:date>
    </item>
    <item>
      <title>Hello Zaheer,</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056932#M1168</link>
      <description>&lt;P&gt;Hello Zaheer,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;refer the following link and you can obtain the diag file.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118228-technote-fireamp-00.html&lt;/P&gt;
&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;
&lt;P&gt;Also you can open a case with TAC by adding this diag file.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 12:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056932#M1168</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-10T12:00:30Z</dc:date>
    </item>
    <item>
      <title>Thanks to all, I have fixed</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056933#M1178</link>
      <description>&lt;P&gt;Thanks to all, I have fixed the issue but checking the running services on the endpoints and excluding the necessary ones, the issue was due to a microsoft patch..&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 05:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056933#M1178</guid>
      <dc:creator>zaheer.jahangir1</dc:creator>
      <dc:date>2017-07-19T05:08:11Z</dc:date>
    </item>
    <item>
      <title>Hello Zaheer,</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056934#M1184</link>
      <description>&lt;P&gt;Hello Zaheer,&lt;/P&gt;
&lt;P&gt;Its always important to identify your environment and exclude the necessary process based on the requirements.&lt;/P&gt;
&lt;P&gt;This will improve the performance very well.&lt;/P&gt;
&lt;P&gt;Here is the exclusion guide for your quick reference.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html&lt;/P&gt;
&lt;P&gt;Glad that you could resolve the issue.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 13:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3056934#M1184</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-20T13:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: What kind of scan it is?</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3315120#M1191</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to stop a scheduled scan from the console. we have an automated scan scheduled and we are having issues on the servers . Is there any option to kill it from the console.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 19:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3315120#M1191</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2018-01-20T19:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: What kind of scan it is?</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3759245#M1197</link>
      <description>&lt;P&gt;Can you pls explain me how this AMP works. I have 36 required attentions in my inbox status.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get rid of this 36 attentions&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 20:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-auto-scan/m-p/3759245#M1197</guid>
      <dc:creator>younus.khan</dc:creator>
      <dc:date>2018-12-06T20:55:32Z</dc:date>
    </item>
  </channel>
</rss>

