SEP for Mac: Troubleshooting | UCSF IT (2024)

Overview

SEP for Mac provides anti-virus/anti-malware (AV) protection and network intrusion prevention technologies (IPS), along with added central management and reporting.Its protection technology may inhibit performance or seemingly disrupt any file or folder functionality of your computer.

Most issues should subside after the particular SEP protection technology has accomplished its tasks in searching for potential risks and remedying them if possible.

The SEP for Mac FAQ pagetries to cover common and known issues and is a good place to start if you suspect SEP may be misbehaving.

This document will walk you through (1) SEP for Mac's typical misbehaviors and (2) basic troubleshooting guidelines,as well as (3) how to temporarily disable SEP protection technologies and (4) how to get log information that may be needed when calling the Service Desk for further assistance.

Common behavior from the SEP for Mac client

Generally, the UCSF SEP client policies are set to allow end users to temporarily disable the SEP protection technologies as a way to help them troubleshoot issues.Before we discuss that optionas well as other workarounds, here are some common behaviors that can help you recognize if SEP is just doing its job or insteadmay be the cause of anomalous issues.

SEP for Mac contains anti-virus/anti-malware protection technologies. Typically, the most resource-intensive task that SEP for Mac performs is running a full scan of a volume. Potential side effects during file scanning may include:

  • Increased CPU usage
  • Slow disk access
  • Lockoutby a file caused by quarantining actions
  • Blockage of internet traffic deemed to be an attack on or risk to the network

To determine if SEP for Mac is in the middle of a scanning operation, you can check the status:

  • Go to Applications -> Symantec Solutions -> Symantec Endpoint Protection.The status screen should note any active tasks SEP is performing.

Other things to note about scheduled scans:

  • The first scan of any volume may take a long time to complete.
  • After a successfully completed scan, subsequent scheduled scans will take less time, since the client should skip files that have not been modified since the last scan.
  • Scheduled scan(s), defined in policy, are typically set for times that will cause the least amount of impact to the workday (e.g., in the middle of the night or very early in the morning).
  • If a machine was powered down during a scheduled scan, the scan will resume once the computer is powered on again.

Regarding Time Machine volumes:

A Time Machine volume containing a long history will take a very long time to complete, because each time interval on the backup will be scanned as though it were an entire system. To mitigate thisissue, we recommend using one of the following:

  • Only mounting Time Machine volumes when needed
  • Starting a new Time Machine volume after installing the SEP for Mac client
  • Maintaining Time Machine on a smaller volume

Temporarily disabling the SEP client

Although disabling SEP is not recommended, the quickest way to determine if an issue is being caused by SEP's protection technologiesis to "disable" the client temporarily to see if the issue goes away.

In the next section, we will discuss how to examine logs to determine what SEP is doing, which is the preferred method to rule out SEP as the cause of unwanted behavior.However, the feature of allowing end users to "disable SEP" provides an easy way to set the SEP client into a pass-through mode, allowing you to determine whetherone of SEP's protection technologies is interfering with a task you need to accomplish and know to be benign.

To temporarily disable the SEP Auto-Protect feature:

  1. In the top menu bar, to the far right, click the Symantec QuickMenu icon.
  2. From the drop-down list, select OpenSymantec Endpoint Protection.
  3. From the left column menu list, select Intrusion Protection, then slide the green bar left for VulnerabilityProtectionand Firewall.
  4. From the left column menu list, select Device Control,then slide the green bar left for Device Control
  5. Please remember to re-enable the functions following the tests to ensure maximum protection of the computer asset.

To re-enable the SEP Auto-Protect feature:

Wait for a few minutes (the central policy should force the client re-enable itself shortly). You can alsofollow the same procedures used to disable the feature, but in step 3, choose Enablefor the protection type.

To stop an active scanning process:

  1. Go to Applications -> Symantec Solutions -> Symantec Endpoint Protection.
  2. If a scan is in progress, you should be presented with an option to postpone or cancel it.

Communications issues for updates to definitions and policies

To ensure the client is communicating and is managed properly by the endpoint servers:

  1. Select the Symantec client tray icon, located at the top right corner of the screen.
  2. Select Open Symantec Endpoint Protection,select Management from the left hand column
  3. Verify that the Connection Status says Connected and specifies the SEP managementto which it's connected.

    SEP for Mac: Troubleshooting | UCSF IT (1)

Checking logs on a Mac

  1. Go to Applications -> Symantec Solutions -> Symantec Endpoint Protection.
  2. Click on Activity from the left hand column.
  3. Click on Security History
  4. Click on Virus Scansand then you can specify which day to review the scan logs

Installation logs

SEP for Mac installation logs are stored in the system's install logs:

  • Review the file /private/var/log/install.log.
  • The phrase "Symantec Endpoint Protection Installation Log" will appear at the beginning of the installation cycle. It isalso accessible through the Console application utility.

Additional logs

Information on exporting the logs mentioned abovecan be found in the Symantec Knowledge Base Article TECH214527.

Advanced (tech-savvy) users can review more logs by following the instructions found in the Symantec Knowledge Base Article TECH134761, which covers using the GatherSymantecInfotool from Symantec.

Uninstalling a SEP client

A common troubleshooting step would be to uninstall and reinstall the SEP client:

  • Instructions for uninstalling the SEP client can be found on the SEP for Mac FAQ documentation page.
  • After uninstalling SEP client, re-download a new client installer from https://software.ucsf.edu/content/endpoint-protectionand reinstall the client.

Reporting issues and getting additional help

Gather the Troubleshootinginformation found on the client. Thiswill provide useful information (e.g., versions, communication settings, actions, updates).

  1. Go to Applications -> Symantec Solutions -> Symantec Endpoint Protection.
  2. Click on Help menu option found at the top of the computer screen.
  3. Select Gather Support Information from the menu.
  4. Type in the account password for the computer when prompted to install the new helper tool.
  5. Wait for the system to gather the system information.
  6. Click OK on the dialog box Symantec Endpoint Protection would like to access files in your Desktop folder.
  7. A dialog box will appear stating Done Gathering Data. Look on the desktop for the file Symantec Support Data.zip
  8. Contact the Service Desk by visiting https://ucsf.service-now.com/ess/or calling415-514-4100.

Advanced troubleshooting for the tech-savvy

The majority of Symantec's documentation (e.g., how-to articles, Knowledge base articles, forum discussions) is fully open and accessible to anyone.Mostare technical, but they can be very informative.

A good place to start for advanced troubleshooting of SEP for Mac issues is Symantec's office "SEP for Mac FAQ" Knowledge Base article at:

https://support.symantec.com/en_US/article.TECH240292.html

SEP for Mac: Troubleshooting | UCSF IT (2024)
Top Articles
MTN MoMoPay - Digital Mobile Wallet Payments | Payfast by Network
FAQs • How long does it take for an EFT (electronic funds tr
Tripper Bus Promo Code
FTC challenge of biggest grocery deal ever captures Albertsons exec's surprise: 'You are basically creating a monopoly in grocery with the merger'
Vcuapi
Ads Supplier Portal
The 10 Craigslist Guys You’ll Live With in DC
Find Office Depot Close To Me
Seething Storm
Pa Speedtest Rcn Merlin
Pay My Venus Bill
Dwc Qme Database
Loreal Smith Sarkisian Age
Unblocked Baseball Games 66
Victoria Tortilla & Tamales Factory Menu
Who Is Mikaylah? Age, Boyfriend, Net Worth, Wiki & More
M&M Imports Fontana
War Thunder M60
Walmart Listings Near Me
Prettyaline
Oscoda Michigan Map: Discover the Charm and Beauty of This Scenic Destination - 200smichigan.com (UPDATE 👍)
Tcu Jaggaer
Flowers Jewel Osco
Walker Medical Diagnostics Patient Portal
Used Chest Freezer For Sale Craigslist
Streameast Mlb Playoffs
Madewell Valley Fair
Southwest Tracker Live
Musc Children's Health After Hours Care - North Charleston
Baris Atay Twitter
Prentice Hall Biology Workbook Answers Pdf
Different distance with GPS/Ultratrack - Instinct - Outdoor Recreation Archive
Pcc Skilled Nursing Login
Erlebnispark Paaren – Ausflugsziel mit Kindern in Brandenburg
Florida Atlantic University
Crime Graphics Tcsd
Outlet For The Thames Crossword
Ascension St John Tulsa Patient Portal
Pinpoint Recruitment Fort Worth Tx
Ezpz Escape Answer Key
Brenda89 Camsoda
Rightmost Symbol On Alaska's State Flag Nyt
A Compressed Work Week Provides All Of The Following Except
Millie Bobby Brown Tied Up
Reno.fbsm
Displacement avec Danielle Akini (Scrum master)
Ihs Hockey Systems
Frommer's Philadelphia & the Amish Country (2007) (Frommer's Complete) - PDF Free Download
Celebrating 50 years, Mellow Mushroom co-founder shares the story of the trippy pizza chain’s humble beginning
Baldurs Gate 3: Komplettlösung, Guides, Tipps und Tricks
Latest Posts
Article information

Author: Terrell Hackett

Last Updated:

Views: 6076

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.