cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2054
Views
0
Helpful
2
Replies

cisco Amp pc3000 not detecting malware using local protect DB in standalone connected mode

cisco Amp pc3000 not detecting malware using local protect DB in standalone connected mode.

 

--> Verified the protect DB and it shows present.

--> Using default audit policy with file audit option

-->tested malware by downloading EICAR file

eicar_com.zip (2546dcf..9eedad)[ZIP Archive] was Created by explorer.exe (d5bc504..4c58ef)[Unknown].

 

Let me know if any suggestions.

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Hard to say what's going on without looking at your configuration directly. I would recommend opening a TAC case and the engineer should be able to sort out the issue for you.

Thanks @Marvin Rhoads .

 

Found the issue, its related to protect DB.