Quantcast
Channel: Ivanti User Community : Discussion List - All Communities
Viewing all 15294 articles
Browse latest View live

Agent Health Questions

$
0
0

I never really used agent health in the past and have started looking into again today. Some things confuse me about it. It seems there are three pieces to it and I'm not fully understanding how they all connect. You have a bootstrap task, an agent setting (which isn't even part of agent config), and patch manager definitions (which are much smaller in number compared to the amount of repair items in the agent settings).

 

Do we really have to manually run a change settings against all agents to use agent health or does the default agent health setting come into play? I couldn't find evidence of this in the registry. Having to deploy an agent AND run a change settings task seems odd to me.

 

How do the agent health patch definitions relate to the actual agent settings?

 

What happens if you use one without the other?

 

Some of the definitions reference specific file versions. I just updated to SU5, but have not updated most agents yet. Would these definitions start replacing files on those updated agents?

 

What part is the bootstrap task working in conjunction with? It looks like it just kicks off a vulscan for type 3 which would lead me to believe it works with the definitions.


Inventory scan failed :ldiscn32: the inventory server "XXX" did not respond

$
0
0

Recently  we are facing issue with inventory scans not working on most of new client machines. We are able to successfully push the Landesk inventory agent  to a new PC. It seems to install fine but the PC is still sitting in Pending Unmanaged Client Deployment. It fails when sending scan results to the core server. When I tried to run a inventory scan manually ,it fails and displays the below error.

 

 

 

Inventory Services seem to be up and running within the PC and core server.
I can telnet from the PC to the core with ports 5007.
Windows firewall is disabled.

 

 

Appreciate your timely help and support on this

 


Next, I havent configured anything under cloud services appliances,does it have anything do with this inventory scan fail?

 

Inventory scan isn't updating Custom Data values

$
0
0

Last week I added some Custom Data fields (registry values for Java Update info).  After the inventory scan, the values showed up for the machines (JavaRT & Policy)

Untitled.png

 

Over the weekend I ran a job to update the registry enties to what we require and inventory got updated as picture above.   However, upon reboot, the registry entries reset to the original values (that;s a different can of worms).

 

The Inventory has not reverted even with a FULL SYCN SCAN.   If I use REGEDIT on the machine the values are different then the LDMS Inventory.

At this point I can't trust the Custom Data I have in inventory.

 

How can I get this corrected?

 

I'm running LDMS 9.0, SP3.

 

Thanks for your help.

Is there a auto reconnect setting in Velocity - Endless loop problem?

$
0
0

Hi, I have just started using Zebra TC8000 with Velocity in our warehouse and we are seeing some issues with the RF gun getting into a endless loop when the operator try to wake up the device

when the gun is ldle under than 10 min  and it also happened a few times during sign in.   User has to exit Velocity and then activate the Velocity to sign back in and it work.  

 

We do not seem to have this problem with the old Window CE RF gun . 


Is there some reconnect setting or retry on loss setting that is on Velocity that we can try change or is this a hardware setting on the device ?

 

 

 

Where to start with MS critical Updates?

$
0
0

Hello,

 

I've started using Patch manager and completely understand the way it works technically.

 

My aim is now to make sure all our Ivanti clients are patched with MS critical updates. I just don't know where to start. Should i take all MS critical definitions and include them in a rollout project ? Should i only start with the current/last month ?

 

if you have advice or can explain how you manage it, i'd be glad.

 

For your info, some of my clients used WSUS where some others never had any patch. Clients are mainly W10 (different build) and few Windows 7.

 

I know the question could be difficult to answer (or too long) but i'd just be on the right tracks right now.

 

Thank you.

 

David.

LOG-files auf DSM-Server (C:\ProgFiles(x86)\CommonFiles\enteo\NiLogs\Distribution

$
0
0

Hallo,

 

mittlerweile ist das "NiLogs-Verzeichnis" auf unserem DSM-Server auf fast 30GB gewachsen (\enteo\NiLogs\Distribution\), und täglich kommen ca. 500MB an neuen Log-files (JobQueue_NPC) hinzu. Hauptinformation in den Logfiles ist, dass alle files bereits aktuell sind ( ... is already up to date). Wir sind doch etwas über den schnellen Wachstum überrascht.

  1. Welche Empfehlung können sie uns bezüglich der Behandlung dieser Log-Files empfehlen? Gibt es diesbezüglich ein Best Practise?
  2. Gibt es eine Möglichkeit das Wachstum der Log-Files zu reduzieren?
  3. Gibt es ein Tool für die Verwaltung der Log-Files?

 

Danke
Markus

Capture pinned documents to Office shortcuts in taskbar Ivanti Workspace Control

$
0
0

We're facing the following issue in our Citrix with Invanti Workspace Control environment.

 

When a user pins a word document to de Word-icon in the taskbar two strange things happend:

1. After logout and login the pinned item disapears

2. When a user pins a item he is not able to open it. The following error occured: "The item you selected is unavailable. It might have been moved, renamed or removed. Do you want to remove it from the list?"

 

When i right-click the pinned item and choose "open" everything works fine!

 

Is there anyone who has an idea?

Office 2016 shortcuts not pinned to Startmenu Windows 2012R2

$
0
0

We are using Ivanti Workspace Control 10.2.0.1 and we have the following problem.

 

When we configure Office 2016 applications and configure to pin the tile to the Startmenu it does not appear in the startmenu. Pinning to the taskbar is working correctly.

As far as I can tell now we have this problem only with the Office 2016 applications.

 

We also have Office 2013 applications configured the same way and we do not experience that problem with Office 2013.

 

Does anyone know a solution? Because this is very annoying for the users.


Distribution "stillgelegt" - Falsche Vergabe von Pollingintervallen?

$
0
0

Hallo,

ich weiß, es gibt keine dummen Fragen, sondern nur Dumme Antworten, und ich weiß, dass Leute wie ich eigentlich die Finger von Dingen lassen sollten, von denen Sie nichts verstehen (oder nur wenig). Ich stand auch schon im stillen Kämmerchen und habe mich geschämt, das habe ich hinter mir. Nun, aller Hoffnung entledigt wende ich mich an ein Forum, welches mir in der Vergangenheit stets interessantes und wissenswertes vermittelt hat, in der Hoffnung, dass sich hier ein Ansatz findet, der mir aus meiner Misere heraus hilft.

 

Was ich eigentlich möchte ;-):

In einem Versuch die Pollingintervalle zu optimieren, habe ich deine Distribution scheinbar "abgeschaltet" Mag hier das falsche Wort sein, aber so stellt es sich dar.

Ich finde in meiner Infrastruktur eine Organisationseinheit mit diversen Sites. Diese Sites enthalten allesamt jeweils ein Depot und einen Managementpoint. Zwei Sites enthalten jeweils ein Repository, einmal das Haupt Repository, von wo aus auf die Sites Verteilt wird und ein weiteres in der Site, an der ich arbeite. Zweck ist es hier die F7-Installationen beim testen zu beschleunigen.

Ich habe an verschiedensten Stellen an den Pollingintervallen der Distribution herumgeschraubt und zeitweise war es tatsächlich so, dass die Distribution an bestimmten Sites schneller los lief und die Software dort schneller zur Verfügung stand (für die Zuweisung auf dortige Rechner).

Leider ist mein Optimierungswahn nach hinten losgegangen was mich zu der Frage führt, welche Werte für die Distribution angemessen sind und wo (Site / Depot) sie einzustellen sind.

Im speziellen geht es mir um die Intervalle für das Polling der Datenbank (ICDB), Repositorys, Paket-Vorbereitung und PaketDateien.

Es gibt wohl eine Hierarchie mit Vererbung und alle Werte außer bei einer Site sollen 0 sein.... Da bin ich dann ausgestiegen.

 

Bitte hier freundlich um Hilfe.

vielen Dank

Michael

ISM 2018.1 Attachment issue

$
0
0

Hi, We're having an issue with drag/drop attachments on ISM 2018.1 (see below) . We had this issue in Chrome, with 2017.3 and I applied the patch listed here: HEAT Attachment Error which fixed the issue.

 

However since the upgrade we now get the issue in IE. If you press the attach button, and then walk through the wizard it works without issue, it's only drag and drop across IE and Chrome. I've searched the KB to no avail, anyone have any ideas? I attempted reapplying the patch in case that caused the issue, to no avail.

 

When dragging/dropping you are prompted that you've been logged out due to inactivity (despite just logging in) and then the error "upload failed with error: undefined"

 

Pressing OK, and then Renew corrupts the attachment giving it a zero size.

 

 

EPM 2018.1 - LDAP Group membership issue

$
0
0

Hi, we're on-prem customer and I've noticed some odd behaviour, it's either on the core/DB or agent, I can't quite work out which one.

 

The inventory on machines is not recording the LDAP group membership properly. For example, my laptop is in 4 different AD groups, EPM is only showing two, but appears to have mix and matched the records. This only appears to be affecting the machines LDAP group info, user group info is fine.

 

ldapwhomai reports the group membership properly, I ran an outputted inventory scan and found the below, which seems to suggest it's the agent mixing and matching the memberships:

LDAP Groups - Machine - (Display Name:P) - Name =CN=PG-SW-Pilot Group,OU=Software,OU=Standard Permission Groups,OU=Standard Groups,OU=Groups,OU=User and Group Assets,DC=insurance,DC=lan

LDAP Groups - Machine - (Display Name:P) - Description =Pilot Group for Software Deployments

LDAP Groups - Machine - (Display Name:P) - Name =CN=PG-SW-Google Chrome,OU=Software,OU=Standard Permission Groups,OU=Standard Groups,OU=Groups,OU=User and Group Assets,DC=insurance,DC=lan

LDAP Groups - Machine - (Display Name:P) - Description =Add machines for google chrome deployment

LDAP Groups - Machine - (Display Name:D) - Name =CN=Domain Computers,CN=Users,DC=insurance,DC=lan

LDAP Groups - Machine - (Display Name:D) - Description =All workstations and servers joined to the domain

LDAP Groups - Machine - (Display Name:P) - Name =OU=Portable,OU=Swansea,OU=Clients,OU=Hardware Assets,DC=insurance,DC=lan

 

If I read this right (and I could well be wrong) it's trying to list the groups using the same display names, i.e. all with the display name of "P" - one for "Name =CN=PG-SW-Pilot Group" and one for "Name =OU=Portable,OU=Swansea,OU" and finally "ame =CN=PG-SW-Google Chrome"


I've tried uninstalling the agent/deleting from the console and reinstalling to no avail.

 

Tried following this: How to set up and configure policies to use LDAP Groups or LDAP Containers  but I don't seem to get any different results.

 

I've just changed the inventory history to 1 day (we've only just migrated so don't much history to keep) in case it's something in the history causing the issue. But I don't understand how when I get the above output on a manual scan on my computer. I would assume if it was the history or database I should only see that issue on the console, not output on the agent.

 

Can anyone recommend other settings/logs I can check for what might be causing this issue?

2016.3 SU5 upgrade to 2017.3 SU5

$
0
0

Actual facts:

 

Core: Windows Server 2012 R2, >36000  clients.

 

Last weekend we performed the upgrade for our productive Core. Unfortunately we got in troubles. Not because the upgrade, it went well. We find out that after upgrade, all the clients must be immediately upgraded from 2016.3 SU5 to 2017.3 SU5 because remote control is not working, having the error "the signed right document was not valid. authentication failed".

 

In the community are some workarounds but these are working for small environments not for big ones, like ours....how can someone from Ivanti can assume that we can upgrade more than 36000 clients at once and in the very next day we will have all clients upgraded? This is a long medium/long term project(1-2 months).

All previous upgrades allow us some time to upgrade our clients. We are at the 4rd major upgrade but we never had this problems until now.

 

Regarding Ivanti communication with their clients, very disappointed. Where is written a disclaimer for upgrade to 2017 from a lower version where is sentenced that remote control will not work if do not upgrade also the clients ? Or will not work if we do not do tricks with issuer.exe or with security settings from Remote  Agent Settings?

 

Even if we miss the disclaimer, such a major change in the security side, must assure your clients that they can still have working clients into the console. Ivanti never did such major change, all the upgrades giving the possibility to the costumers to have enough time to upgrade, considering their own specific environment and rules.

UNINSTALL .EXE AND .MSP PATCH

$
0
0

Hi There ,

 

I am new to the world of ivanti , and i just have a little problem !:!

 

i pushed some adobe patch yesterday , and i have some users that complain of adobe problem

 

i want to uninstall the patches from the console but the option is grayed !!!

 

Is there any way to uninstall them from the consol !!!!

 

Hope get answer

 

Thank youuu

Issues with Office online Featured Templates not populating.

$
0
0

We've recently deployed a GPO to enable Office Online.  We have about 77 users that are standard users with iVanti Application Control installed (v10.1), we have had reports of Office applications going "Not Responding" which results in the application crashing.

What we have noticed is that the Office Online Featured templates do not populate and we have to sign these users out, then back in to resolve the issue.

 

Seeing this is affecting no one else (8000 + users) but these standard users with Application Control installed, it's more than likely an issue with Application Control... Has anyone experienced issue like this?

Use of Alerts in Xtraction 2018.3

$
0
0

can someone please put some light on Use of Alerts in Xtraction 2018.3 and how to enable the service


Unable to update Default Record Count setting

$
0
0

Xtraction is upgraded to 2018.3 and now Unable to update 'Default Record Count' setting from GUI under Administration-->Setting option

 

We can see the below error in logs, verified the permissions are same on old running server on Xtraction installation directory.

 

Please advise on what could be the issue

 

2018-09-28 11:31:55,202 ERROR Xtraction.Web.API.Controllers.AdministrationController - Failure

System.UnauthorizedAccessException: Access to the path 'D:\Program Files (x86)\Xtraction\Data\Configuration\settings.dat' is denied.

   at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)

   at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)

   at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share)

   at Xtraction.Streams.Service.Impl.FileHandler.OpenFileWrite(String path, FileMode mode)

   at Xtraction.Context.Managers.Impl.CurrentSettingsManager.StoreSettings()

   at Xtraction.Service.AdministrationService.UpdateSettings(ClientSettings settings)

   at Xtraction.Web.API.Controllers.AdministrationController.UpdateSettings(ClientSettings settings)

Clients not reporting to the console

$
0
0

Hi,

 

we have a number of clients (200+ of 6000 total) that have the "Last reported settings" 1 month or more old despite the fact that the clients are online.

Capture.JPG

 

Vulnerability scans fails on this clients because C:\ProgramData\vulscan\AgentBehavior_XXX.xml does not exist.

 

This is an extract of PolicySync.log :

 

Wed, 29 Aug 2018 17:31:41 ValidateSignature finished

Wed, 29 Aug 2018 17:32:00 ExecuteWithElevatedRight: LocalExecute succeeded with ExitCode=-1917648429

Wed, 29 Aug 2018 22:47:52 ValidateSignature start

Wed, 29 Aug 2018 22:47:52 ValidateSignature: Removing any leftover temporary signature files...

Wed, 29 Aug 2018 22:47:52 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

Wed, 29 Aug 2018 22:47:52 ValidateSignature finished

Thu, 30 Aug 2018 11:09:00 ValidateSignature start

Thu, 30 Aug 2018 11:09:00 ValidateSignature: Removing any leftover temporary signature files...

Thu, 30 Aug 2018 11:09:00 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

Thu, 30 Aug 2018 11:09:00 ValidateSignature finished

Thu, 30 Aug 2018 11:12:10 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 12:01:53 ValidateSignature start

Thu, 30 Aug 2018 12:01:53 ValidateSignature: Removing any leftover temporary signature files...

Thu, 30 Aug 2018 12:01:53 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

Thu, 30 Aug 2018 12:01:53 ValidateSignature finished

Thu, 30 Aug 2018 13:04:48 ValidateSignature start

Thu, 30 Aug 2018 13:04:48 ValidateSignature: Removing any leftover temporary signature files...

Thu, 30 Aug 2018 13:04:48 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

Thu, 30 Aug 2018 13:04:48 ValidateSignature finished

Thu, 30 Aug 2018 13:04:48 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 13:19:11 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 14:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 15:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 16:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 17:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 18:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 18:19:12 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 19:19:13 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 20:19:13 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 21:19:13 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 22:19:14 ExecuteWithElevatedRight: LocalExecute failed

Thu, 30 Aug 2018 23:19:14 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 00:19:15 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 01:19:15 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 02:19:14 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 03:19:15 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 04:19:15 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 05:19:16 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 06:19:16 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 07:19:16 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 08:19:17 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 09:19:17 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 10:19:17 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 11:19:17 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 12:19:18 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 12:45:10 ValidateSignature start

Fri, 31 Aug 2018 12:45:10 ValidateSignature: Removing any leftover temporary signature files...

Fri, 31 Aug 2018 12:45:10 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

Fri, 31 Aug 2018 12:45:10 ValidateSignature finished

Fri, 31 Aug 2018 12:45:10 ExecuteWithElevatedRight: LocalExecute failed

Fri, 31 Aug 2018 19:19:17 ExecuteWithElevatedRight: LocalExecute failed

Sat, 01 Sep 2018 13:19:13 ExecuteWithElevatedRight: LocalExecute failed

Sat, 01 Sep 2018 13:40:15 ValidateSignature start

Sat, 01 Sep 2018 13:40:15 ValidateSignature: Removing any leftover temporary signature files...

Sat, 01 Sep 2018 13:40:15 CleanupAnyLeftoverTemporarySignatureFiles: There were no leftover temporary signature files, exiting...

 

 

Client Agent version: 11.0.0.1091

 

 

Any suggestions?

AppSense EM Management and Personalization Server Load Balancing using F5

$
0
0

Hi Experts,

 

We are looking to implement AppSense Desktop Now 10.1 from the ground up and intend to place the EM Management and Personalization Servers in the Primary and DR datacenter behind an F5 LB in an Active-Active Setup.


Do we have some best practice recommendations?https://www.htguk.com/configuring-citrix-netscalers-for-load/

 

I have been through the below links:https://www.htguk.com/configuring-citrix-netscalers-for-load/


& https://community.ivanti.com/servlet/JiveServlet/downloadBody/46174-102-4-136291/Ivanti%20UWM%20Load%20Balancing%20-%20B

 

While they are excellent I am looking for some deeper dive from the community incase there is some experience.

 

Any help or guidance will be much appreciated.

Printers not mapping, sometimes.

$
0
0

Hello Ivanti Community,

 

We have an issue where "sometimes" people do not get their printers when logging onto our Citrix 7.6 environment. They are removed at log off and re-added at logon. Printers aren't hidden or secured by anything.

We cannot exactly pin-point when or how it starts and we cannot find any relevant logging. It does happen however.

 

We also have been able to confirm it happens when they log off and on again, several times in a row, also sometimes.

Only when we log the users off via RDP it works again. Which makes no sense to us.

 

Also when i go to the printer servers via Windows Explorer the printers list like expected. Only when you right click and press connect you get a message saying the driver won't install. It does do this with out old (hidden) backup print server.

 

I know i am being a bit vague but this is all we have been able to figure out. Does anyone have any idea where in ivanti i can turn on some logging?

Or do i need to provide some extra details for trouble shooting? I hope you guys can help me figure this out because our team is really puzzeled. I hope you guys can point me in the right direction.

 

This is my first time posting so sorry if i make any beginner mistakes

 

- Ton

Write query to find missing roles, Is it possible to write query to find end users who are missing a role that should be on all end users

$
0
0

All of our end users should have the EndUser role but some do not.  Is it possible to write a query to identify all of the end users who do not have this role.

Viewing all 15294 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>