<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outdated Definitions in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763579#M4776</link>
    <description>&lt;P&gt;Hi both,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We didn't get this working in the end, or at least I never found out the cause. The endpoints that hadn't been updated would suddenly show as compliant days later - so it could be the bug Jetsy linked. I didn't make any changes myself to our settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Dec 2018 09:10:18 GMT</pubDate>
    <dc:creator>harrysocker</dc:creator>
    <dc:date>2018-12-14T09:10:18Z</dc:date>
    <item>
      <title>Outdated Definitions</title>
      <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3365498#M4720</link>
      <description>&lt;P&gt;I'm currently trialling AMP for Endpoints and have found there's no consistency with the status of the connectors I've installed on machines. Some show that the definitions are up to date. Some show as 'outdated definitions'. There isn't anything referenced in the documentation I've seen or on the forum.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to force the clients to update, either from client side or the portal? What prompts the connector to download new definitions that are available?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any help.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3365498#M4720</guid>
      <dc:creator>harrysocker</dc:creator>
      <dc:date>2019-03-09T01:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Outdated Definitions</title>
      <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3365924#M4721</link>
      <description>&lt;P&gt;Hello Harry&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you added the required server address based on the Cloud that you have registered account with ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to schedule the new&amp;nbsp;connector&amp;nbsp; updates, then you can schedule it accordingly in the Management &amp;gt; Policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Apr 2018 06:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3365924#M4721</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-04-14T06:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Outdated Definitions</title>
      <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763502#M4745</link>
      <description>&lt;P&gt;OP did you get this sorted? I'm having the same issue as you. I have the policy set with these two options and these are all that I can see that would be required:&lt;/P&gt;
&lt;P&gt;1. "automatic content updates" this is checked / enabled&lt;/P&gt;
&lt;P&gt;2. "content update interval" this is set to 1 hour which is the default&lt;/P&gt;
&lt;P&gt;Both options above around found in edit policy &amp;gt; Advanced &amp;gt; TETRA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/94963"&gt;@Jetsy Mathew&lt;/a&gt; - the OP is talking about TETRA definitions, not software or AMP client update&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 06:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763502#M4745</guid>
      <dc:creator>tonypearce1</dc:creator>
      <dc:date>2018-12-14T06:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Outdated Definitions</title>
      <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763529#M4757</link>
      <description>&lt;P&gt;Hello Tony&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this was something working previously? In the following link there are server address that you should allow for the successful tetra definition update based on the cloud that you have registered with. Just make sure based on the cloud (EU,APJC,NAM) allow the traffic and make sure no inspection happens on the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If its still doesnt work then its better to get a wireshark capture&amp;nbsp;for a day or so from any of those workstation which shows definition outdated along with the diagnostics file and submit it to the Cisco TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just fyi there was a known bug which got fixed sometime back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj58637/?reffering_site=dumpcr" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj58637/?reffering_site=dumpcr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if the issue has started recently then please contact the Cisco TAC and we will help you on the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 07:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763529#M4757</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-12-14T07:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Outdated Definitions</title>
      <link>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763579#M4776</link>
      <description>&lt;P&gt;Hi both,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We didn't get this working in the end, or at least I never found out the cause. The endpoints that hadn't been updated would suddenly show as compliant days later - so it could be the bug Jetsy linked. I didn't make any changes myself to our settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 09:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/outdated-definitions/m-p/3763579#M4776</guid>
      <dc:creator>harrysocker</dc:creator>
      <dc:date>2018-12-14T09:10:18Z</dc:date>
    </item>
  </channel>
</rss>

