did you see Threat Events on affected machines ? 1202: On-Demand Scan started (Info) ?
also you can event in MA monitor windows if scheduled task started or not.
I had opened a ticket with support but by the time they called me back, suddenly our computers started reporting scans after nothing for over a month. We went from ~400 clients completing scans in the last 7 days to nearly 2300.
I did change one option, our quick scans are no longer set to scan when idle. This may be something that impacts Windows 10 more than older OS. We have moved over to primarily Windows 10 in the last year. Maybe Windows 10 doesn't report idle times correctly to software or something. Currently 1709 migrating to 1809. One computer I checked had no scanned since September despite being plugged in a not used but once in a great while.
There is something wrong with scan on idle and windows 10, our decision was not to use with option.
I am running scan any time, exclusion is presentation mode and if machine on battery.
Ok, I'm glad someone else came to the same conclusion. We are now set to the same as you and it appears to be working good since the change.
We don't use scan on idle in our environment since we manage servers. The issue still there though.
Hello Everyone,
In our environment, i haves this log:
2020-03-08 20:00:00.656 masvc(2908.2936) scheduler.Info: Scheduler: Invoking task [On-Demand Scan - Full Scan]...
2020-03-08 20:00:00.659 masvc(2908.2936) scheduler.Info: The task On-Demand Scan - Full Scan becomes active
2020-03-08 20:00:43.639 masvc(2908.2936) scheduler.Info: The task On-Demand Scan - Full Scan is successful
But, i don't have the any ID envents about the Scan.
Thanks,
Enable event "Server Settings" --> Event filtering
Additionally, Event id 1202 and 1203 have severity Informational. In ENS Common select "All" for On demand scan events. By default only "Critical and Alert" severity events are logged.
In the EPO server settings, I have this events checked.
Included this-> 34852; 34853; 38454; 38455; 34900
Look in the log file OnDemand_Activity, is empty.
Some more information, I used the versions:
Agent: 5.5.1.388
Endpoint Plataform 10.6.1.1724
Endpoint Threat Prevention: 10.6.1.1777
enable 1202 AND 1203
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: