<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AMP - Outdated Definitions, Endpoints not checking in after Connector Update in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776924#M173</link>
    <description>&lt;P&gt;We are seeing several endpoints not checking in or receiving definition updates after&amp;nbsp;being updated to connector version&amp;nbsp;&lt;SPAN&gt;6.2.3.10814. There is nothing unique about these machines in our environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The last 3 events for these machines are as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint started a product update&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint is currently unprotected. A reboot is required to finish the update and restore Connector protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint requested a reboot&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After rebooting, the machines do not check in and the last seen date is when the connector was updated. Subsequent reboots have no effect. Is there a way to force these machines to check in or force an update?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:07:26 GMT</pubDate>
    <dc:creator>phonehome</dc:creator>
    <dc:date>2020-02-21T05:07:26Z</dc:date>
    <item>
      <title>AMP - Outdated Definitions, Endpoints not checking in after Connector Update</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776924#M173</link>
      <description>&lt;P&gt;We are seeing several endpoints not checking in or receiving definition updates after&amp;nbsp;being updated to connector version&amp;nbsp;&lt;SPAN&gt;6.2.3.10814. There is nothing unique about these machines in our environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The last 3 events for these machines are as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint started a product update&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint is currently unprotected. A reboot is required to finish the update and restore Connector protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;endpoint requested a reboot&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After rebooting, the machines do not check in and the last seen date is when the connector was updated. Subsequent reboots have no effect. Is there a way to force these machines to check in or force an update?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776924#M173</guid>
      <dc:creator>phonehome</dc:creator>
      <dc:date>2020-02-21T05:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Outdated Definitions, Endpoints not checking in after Connector Update</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776935#M174</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/398009" target="_self"&gt;&lt;SPAN class=""&gt;phonehome&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;After the reboot, does it reflects the latest connector version and is the connector status is still showing as connected or disconnected in the endpoint?A diagnostic support file from any of the endpoint would be helpful to verify the definition update logs to know more about the issue. As per my knowledge there&amp;nbsp;is no force way of updating tetra definitions.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Also, can you verify if there is any connection break towards the tetra definition update server based on the cloud that you have registered with? Based on the server address you can even run a wireshark capture and leave it for a day in any of the endpoint client to see if there is any connection break. You can filter the packet capture and it&amp;nbsp; will help you to confirm if the communication is successful or not.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Let me know if you have any queries on same.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Jetsy&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776935#M174</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2019-01-10T14:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Outdated Definitions, Endpoints not checking in after Connector Update</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776944#M175</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/398009" target="_self"&gt;&lt;SPAN class=""&gt;phonehome&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a quick step to check the successful communication, you can try running the following from any of the endpoint cmd.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-style: inherit !important; font-weight: inherit !important;"&gt;C:\Program Files\Cisco\AMP\X.X.X\connectivitytool.exe&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-style: inherit !important; font-weight: inherit !important;"&gt;Once you run the script, it will generate a log file which is connectivitytool.exe.log&amp;nbsp;on which you can check the connection status.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-style: inherit !important; font-weight: inherit !important;"&gt;But this will not help you if the connection break is happening intermittently.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-style: inherit !important; font-weight: inherit !important;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-style: inherit !important; font-weight: inherit !important;"&gt;Jetsy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3776944#M175</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2019-01-10T14:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Outdated Definitions, Endpoints not checking in after Connector Update</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3779384#M176</link>
      <description>&lt;P&gt;I've spot checked a few machines and it looks like the AMP service did not start after the update and reboot. The service was set to automatic start up so not sure why this would happen. Any idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 17:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3779384#M176</guid>
      <dc:creator>phonehome</dc:creator>
      <dc:date>2019-01-14T17:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Outdated Definitions, Endpoints not checking in after Connector Update</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3779391#M177</link>
      <description>&lt;P&gt;We haven't seen any instances of the service not starting after the 6.2.3 upgrade.&amp;nbsp; I would recommend opening a TAC case and uploading logs from those endpoints so one of our Techs can take a look at the details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 17:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-outdated-definitions-endpoints-not-checking-in-after/m-p/3779391#M177</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-01-14T17:30:26Z</dc:date>
    </item>
  </channel>
</rss>

