Error 13158645764: server_2 : ERROR: Virus checker NOT started.
Hi,
I am trying to setup CAVA, when i enable services of virus checker the it starts after couple of mintues it says virus checker services not started. And i have started a filesystem scan which is successfully but when i list it shows filesystem not in scan. So what extactly is wrong here and lot of inconsistency
Can anyone help me on this and hope for a quick response.
If you have to start CAVA to get information, that means the CAVA service is stopped. Since you have shutdown=viruschecking set in your viruschecker.conf, that means the NAS will stop the viruschecking service automatically, when the CAVA servers fail to respond.
Also, that might be exacerbated by the high RPCRequestTimeout value you've got set. 85000 milliseconds means you're waiting more than three times longer than expected before trying to contact the next CAVA server in the pool.
There are a few things you do. First, are you observing the server_log for any virus checker warnings? You will see errors with the VC facility in your logs. You can try "server_log server_2 | grep VC" to see what I mean. Second, if you're getting errors, are they low watermark / high watermark messages? If so, this is because the CAVA servers are not keeping up with the scanning workload. You'll need to add more CAVA servers to spread the workload out. If you aren't encountering high watermark issues, you might see other messages in the server_log that could be useful.
Ok, I disabled shutdown=viruschecking so now able to run the virus_checker command and services are running. I checked the CAVA server event logs Found the below ,i will enable the option latter.
From the CAVA server Event Log :
Error :
The AUDIT facility is enabled, but not configured.
The EMC CAVA service will not process events for this facility.
Possible Causes: The required vendor information is not present.
Or a required component is not installed.
Solutions: Check Endpoint entry in registry for AUDIT facility for vendor names.
Install the needed component for the AUDIT facility if applicable and restart the EMC CAVA service.
For the above error followe KB https://support.emc.com/kb/425428 From the KB i have followed 2 step and restarted the CAVA services After which got the below Output
When tried to access \\swoef203\check$ getting the error as
Output From : server_log server_2 -i -s |grep VC
2016-04-14 16:44:18: VC: 3: Invalid access from client 53.8.60.145 to CHECK$
2016-04-14 16:44:18: VC: 3: User does not have the VirusChecking/CEPP privilege:
2016-04-14 16:44:18: VC: 3: Invalid access from client 53.8.60.86 to CHECK$
2016-04-14 16:44:18: VC: 3: User does not have the VirusChecking/CEPP privilege:
EMC VChecking user account is which i am using for server CAVA services logon as well. I am able to access \\swoef203\c$
just stuck here now, what permission am i missing and how to make Account must be local Admin on the Windows ScanEngine Server and on the VNX CIFS Server for CAVA (SxxxFnnn-CAVA) What should be done?
I can't stress this enough - restarting the CAVA service will not fix your issue. You need to review the documentation and set the right privileges on the Domain Account for the CAVA service. This is well-detailed in the documentation - just follow the outlined steps and you'll be okay.
The reason i mention CAVA services is because i wanted to let you as a FYI, i am aware it does not fix the issue. I have gone through the document i am stuck here --> Assign the EMC virus-checking right to the group, in the document it is mentioned to use Celerra Management
Download EMC celerra management tool, I downloaded CelerraCifsMgmt_7.1.72.1 and installed it, the machine which I installed is a 64-bit but the software supports only 32-bit. I tried searching and getting the 64-bit support tool but couldn’t find any.. can you help me get the 64-bit tool?
shivadaimler
1 Rookie
•
24 Posts
2183
0
Posted April 12th, 2016 23:00
And .. i keep entering the start command every time when i need to check virus_checker information. Can it be automated or is this a bug?