Unsolved

1 Rookie

 • 

44 Posts

1623

July 12th, 2021 07:00

Multiple CAVA issues being reported

hello all

3rd time i have tried posting this question, not sure why it keeps marking it as spam?! anyway....

We have 2 x 8 node clusters running 9.1.0.4, each cluster has 4 CAVA Windows servers available to them.

However every few minutes we are getting errors logged with 

ID Started Sev Message
------------------------------------------------------------------------
82315 07/12 15:19 W Resolved: The antivirus software on the server Cluster1Cava01.domain connected to node 3 has errors or is working improperly. Please check the CEE installation guide and the antivirus software vendor's documentation for proper setup.

I have checked the CAVA servers

  • No obvious errors are being reported on the WIndows servers
  • AV is working on them as expected
  • Created a test virus file using the EICAR test file which prompted correct alerts

also checked the Isilon

  • CAVA servers show as enabled
  • Each node shows connections to them

 

so my questions to you all are

What else can I check for this?

What have I missed?

My Guess is that Dell Support won't be able to help as the AV isn't provided by them

 

thanks in advance

Moderator

 • 

7.7K Posts

July 12th, 2021 16:00

Hello NotStopIsilonProblems,

Have you looked at chapter 2 of Dell EMC CEE Using the Common Event Enabler on Windows Platforms guide? https://dell.to/3ebtFU1

1 Rookie

 • 

44 Posts

July 13th, 2021 02:00

hello

thank you for reply

yes I have been through the chapters looking for anything that I may have missed but can't see anything obvious.

Wondering if next week when we apply 9.1.0.8 and reboot the nodes if that will resolve it?

Moderator

 • 

7.7K Posts

July 13th, 2021 10:00

9093438 Hello NotStopIsilonProblems,

There are some changes that are going to be applied in 9.1.0.8. I am not sure if they will resolve your specific issue.

2 Posts

August 19th, 2022 02:00

We have the same errors even on OneFS Version: 9.2.1.14

Enabled the DEBUG / Verbose options on the  CEE server  (v8.9.7.1) / DTD version 2.3.0

https://www.dell.com/support/kbdoc/en-uk/000043513

Ignore the old VNX References and just enable the CEE debug on the AV host

then use MS DEBUGVIEW to see all the messages / scans and errors in real time or output to file 

 

We see these errors pop up about the same time as the Isilon Alerts trigger - but so far unconfirmed

- would be interesting to know if you see the same   

 

CCEECore::CheckHeartBeat AV Returning AV HB Result: 13 - ERROR AV INTERFACE

IOCTL_FSCVIR_CHECK_UNCPATH failure= e0000034(hex)

 

Dell are investigating under an SR - will update if we find a root cause or cure

2 Posts

October 31st, 2022 09:00

So further update - one thing that makes a BIG difference is an old requirement from the VNX - as its related to the Windows Server Caching the Folder it has been by DELL as definitely still relevant - it was not in the earlier Isilon Config guides - might be in newer later versions.

Basically the Windows Server is using a cached view of the Folder - so if files are changed / deleted rapidly the cache is out of date and we get the File not found error - this is sent back to the Isilon as a Windows CEE "event" and triggers an AV Server Warning / Alert.

 

Still looking into the Health state of some of the AV Servers dropping to POOR - and how to spread the CAVA AV Workload as some servers seem to get saturated but there seems to be no way to change the way the Isilon distribute the workload - or increase the 5 Threads that each Isilon node starts to the 4 Target CAVA Servers. This means in our case with not all nodes being front end and engaging in the CAVA AV we only have 4 Active Isilon Nodes (with 5 threads) * 4 AV Server connections 

 

To avoid this condition, you must disable the directory cache on the machines on which CAVA and AV
engines are running by using the following procedure:

1. Open the Windows Registry Editor and navigate to HKLM\System\CurrentControlSet\Services\LanmanWorkstation
\Parameters.
2. Right-click Parameters and select New > DWORD Value.
3. For the new REG_DWORD entry, type a name of DirectoryCacheLifetime.
4. Set the value to 0 to disable DirectoryCacheLifetime.
5. Click OK.
6. Restart the machine

Top