Unsolved
1 Rookie
•
44 Posts
0
1623
July 12th, 2021 07:00
Multiple CAVA issues being reported
hello all
3rd time i have tried posting this question, not sure why it keeps marking it as spam?! anyway....
We have 2 x 8 node clusters running 9.1.0.4, each cluster has 4 CAVA Windows servers available to them.
However every few minutes we are getting errors logged with
ID Started Sev Message
------------------------------------------------------------------------
82315 07/12 15:19 W Resolved: The antivirus software on the server Cluster1Cava01.domain connected to node 3 has errors or is working improperly. Please check the CEE installation guide and the antivirus software vendor's documentation for proper setup.
I have checked the CAVA servers
- No obvious errors are being reported on the WIndows servers
- AV is working on them as expected
- Created a test virus file using the EICAR test file which prompted correct alerts
also checked the Isilon
- CAVA servers show as enabled
- Each node shows connections to them
so my questions to you all are
What else can I check for this?
What have I missed?
My Guess is that Dell Support won't be able to help as the AV isn't provided by them
thanks in advance



DELL-Sam L
Moderator
•
7.7K Posts
1
July 12th, 2021 16:00
Hello NotStopIsilonProblems,
Have you looked at chapter 2 of Dell EMC CEE Using the Common Event Enabler on Windows Platforms guide? https://dell.to/3ebtFU1
NotStopIsilonProblems
1 Rookie
•
44 Posts
0
July 13th, 2021 02:00
hello
thank you for reply
yes I have been through the chapters looking for anything that I may have missed but can't see anything obvious.
Wondering if next week when we apply 9.1.0.8 and reboot the nodes if that will resolve it?
DELL-Sam L
Moderator
•
7.7K Posts
0
July 13th, 2021 10:00
9093438 Hello NotStopIsilonProblems,
There are some changes that are going to be applied in 9.1.0.8. I am not sure if they will resolve your specific issue.
rmh999
2 Posts
0
August 19th, 2022 02:00
We have the same errors even on OneFS Version: 9.2.1.14
Enabled the DEBUG / Verbose options on the CEE server (v8.9.7.1) / DTD version 2.3.0
https://www.dell.com/support/kbdoc/en-uk/000043513
Ignore the old VNX References and just enable the CEE debug on the AV host
then use MS DEBUGVIEW to see all the messages / scans and errors in real time or output to file
We see these errors pop up about the same time as the Isilon Alerts trigger - but so far unconfirmed
- would be interesting to know if you see the same
CCEECore::CheckHeartBeat AV Returning AV HB Result: 13 - ERROR AV INTERFACE
IOCTL_FSCVIR_CHECK_UNCPATH failure= e0000034(hex)
Dell are investigating under an SR - will update if we find a root cause or cure
rmh999
2 Posts
0
October 31st, 2022 09:00
So further update - one thing that makes a BIG difference is an old requirement from the VNX - as its related to the Windows Server Caching the Folder it has been by DELL as definitely still relevant - it was not in the earlier Isilon Config guides - might be in newer later versions.
Basically the Windows Server is using a cached view of the Folder - so if files are changed / deleted rapidly the cache is out of date and we get the File not found error - this is sent back to the Isilon as a Windows CEE "event" and triggers an AV Server Warning / Alert.
Still looking into the Health state of some of the AV Servers dropping to POOR - and how to spread the CAVA AV Workload as some servers seem to get saturated but there seems to be no way to change the way the Isilon distribute the workload - or increase the 5 Threads that each Isilon node starts to the 4 Target CAVA Servers. This means in our case with not all nodes being front end and engaging in the CAVA AV we only have 4 Active Isilon Nodes (with 5 threads) * 4 AV Server connections
To avoid this condition, you must disable the directory cache on the machines on which CAVA and AV
engines are running by using the following procedure:
1. Open the Windows Registry Editor and navigate to HKLM\System\CurrentControlSet\Services\LanmanWorkstation
\Parameters.
2. Right-click Parameters and select New > DWORD Value.
3. For the new REG_DWORD entry, type a name of DirectoryCacheLifetime.
4. Set the value to 0 to disable DirectoryCacheLifetime.
5. Click OK.
6. Restart the machine