Help - Search - Members
Full Version: Kaspersky Security for Exchange 5.5 log file issue
Kaspersky Lab Forum > English User Forum > Protection for Small and Medium Businesses
strafelife
Hello,

I am running into 2 issues with Kaspersky Security for Exchange 5.5. I noticed on another forum (back in 2006) that a user ran into a similar issue.

The kavscmesrv{Date stamp}.log is growing by GB. I noticed the problem when the file system was full, because of Kaspersky Security. Since April 29 (today is May 20th) the log file grew to 22 GB!!!

This is obviously a bug, the software should not allow a log to grow that large, that fast - regardless of whatever issues. I started a ticket with Kaspersky USA tech support to start investigating the problem. As usual (for all the issues I run into), I was told to run the getsysteminfo.exe and of course it appears to be a "corrupt" installation.

My operating system is Small Business Server 2003 (SBS 2003) R2 with all the latest patches from Microsoft. The installation was a default one. I did not change the logging level for the diagnostics in the Management console.

Anyone at Kaspersky have a clue as to what is happening here?

Tybilly
Hello,

You can change debugging level in the administration console of the product. I advise you to try restore the default settings, or to select a lower one.
> See page 111 of the manual.

Also if log files have this size, maybe you can have a problem with your security product on the server, next time it will be necessary to check the content of this logs.

strafelife
The logging levels are set to the default. Everything about this install and configuration is typical and default, I did not deviate at all.

Looking at the log files, I see this type of entry over and over again:

___________________________________________________________________________
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Open log
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Close log
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: _____________________________________________________________________________
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Close log

What is the point of this message?
SergeAD
QUOTE(strafelife @ 21.05.2008 22:39) *
The logging levels are set to the default. Everything about this install and configuration is typical and default, I did not deviate at all.

Looking at the log files, I see this type of entry over and over again:

___________________________________________________________________________
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Open log
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Close log
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: _____________________________________________________________________________
30:04:2008 06:54:26 Anti-Spam Scan Subsystem 0xcd111001 EMR: Close log

What is the point of this message?

please do anti-spam bases update from mmc console. Do you see any errors after finishing update?
strafelife
QUOTE(SergeAD @ 22.05.2008 18:38) *
please do anti-spam bases update from mmc console. Do you see any errors after finishing update?


No error messages at this point. Here are the last few lines:

23:05:2008 15:23:15 Statistics 0xcc912023 The statistics object has not been saved to the statistics subsystem. Error code -2147467259. Query text: INSERT INTO scanstat ( timestamper, recveraddr, senderaddr, verdict, virusname, sclrate, isquarantined, [size] ) VALUES ( NOW(), 'Unknown', 'hidden@hidden.com', 1, 'Unknown', 0, 0, 5367)??
23:05:2008 15:23:48 Licensing 0x4ce2001f Verifying the license
23:05:2008 15:23:49 Licensing 0x4ce21030 Current license key: (HIDDEN.key)
23:05:2008 15:23:49 Licensing 0x4ce21029 Mailboxes found (15)
23:05:2008 15:23:49 Licensing 0x4ce21020 License verification is complete (0)


I get alot of Error code -2147467259 - is that normal?
stanley
same problem - is that normal?
paguti
QUOTE(stanley @ 4.11.2008 13:58) *
same problem - is that normal?

I have same problema; I can delete this files ? any problem?
Tybilly
Hello,

Check that you have the latest version 5.5.1388.0, which can be downloaded from this link.
Some improvements have been made in this new build that are listed on this FAQ.

After the upgrade, delete all logs file and see if they reach such a big size as before.

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.