{"id":8605,"date":"2021-04-21T11:58:26","date_gmt":"2021-04-21T10:58:26","guid":{"rendered":"https:\/\/www.nod32.com.hr\/podrska\/?p=8605"},"modified":"2024-06-19T13:25:49","modified_gmt":"2024-06-19T12:25:49","slug":"eset-protect-dijagnostika","status":"publish","type":"post","link":"https:\/\/www.nod32.com.hr\/podrska\/kb8605","title":{"rendered":"ESET Protect <br>Dijagnostika"},"content":{"rendered":"<!-- ---------------------------------------------------------------------------------------------------- TEMA -->\r\n<h2>Tema<\/h2>\r\n<p>Prikupljanje dijagnosti\u010dkih logova za analizu problema u radu sljede\u0107ih dijelova sustava:<\/p>\r\n<p>\u2022 ESET Protect (EPx) server \/ konzola<br \/>\r\n\u2022 EMagent (ESET Management Agent)<br \/>\r\n\u2022 Endpoint \/ File Security \/ Server Security \/ Mail Security<br \/>\r\n\u2022 Komunikacija izme\u0111u ra\u010dunala u mre\u017ei<br \/>\r\n\u2022 Komunikacija s ra\u010dunalima na Internetu<br \/>\r\n\u2022 Komunikacija s ESET-ovim serverima na Internetu<\/p>\r\n<!-- ---------------------------------------------------------------------------------------------------- UVOD -->\r\n<h2>Uvod<\/h2>\r\n<p>Najbr\u017ei na\u010dini da ustanovite utje\u010de li va\u0161a konfiguracija ESET-ovog sustava ili konfiguracija va\u0161e mre\u017ee na pona\u0161anje pojedinih dijelova ESET-ova sustava:<\/p>\r\n<p>\u2022 Provjerite ima li problemati\u010dno ra\u010dunalo (ili grupa) isto mre\u017eno okru\u017eenje (isti segment, gateway, proxy, firewall profil, &#8230;)<br \/>\r\n\u2022 Provjerite ima li problemati\u010dno ra\u010dunalo (ili grupa) instalirane iste programe i konfiguraciju<br \/>\r\n\u2022 Izdvojite problemati\u010dno ra\u010dunalo iz mre\u017ee (fizi\u010dki ili ga spojite na <em>ad-hoc hotspot<\/em> mobitela)<br \/>\r\n\u00a0\u00a0 \u25cb ako to nije mogu\u0107e &#8211; upotrijebite neki VPN klijent (ProtonVPN glasi za pouzdanog)<br \/>\r\n\u2022 Izdvojite EPx iz mre\u017ee (fizi\u010dki ili ga spojite na <em>ad-hoc hotspot<\/em> mobitela)<br \/>\r\n\u00a0\u00a0 \u25cb ako to nije mogu\u0107e &#8211; upotrijebite neki VPN klijent (ProtonVPN glasi za pouzdanog)<br \/>\r\n\u2022 Instalirajte probno okru\u017eenje &#8220;od nule&#8221; i isprobajte<br \/>\r\n\u00a0\u00a0 \u25cb ako se problem ne pojavljuje &#8211; kopirajte postavke sustava jednu po jednu dok ne na\u0111ete koja stavka ga uzrokuje<\/p>\r\n<h2>Postupak &#8211; Kratko (tl;dr)<\/h2>\r\n<p>Ako gornji testovi ne daju rezultat i problemi se i dalje pojavljuju &#8211; prikupite dnevnike programa iz popisa u nastavku i nastojat \u0107emo u njima prona\u0107i uzrok.<\/p>\r\n<p>&nbsp;<\/p>\r\n<hr \/>\r\n<p><!-- ---------------------------------------------------------------------------------------------------- KRATKO --><\/p>\r\n<h2>[A] Postupak &#8211; Detaljno<\/h2>\r\n<p>Po\u017eeljno je da odaberete barem dva klijenta s kojima ima problema.<\/p>\r\n<p>[<strong>A1<\/strong>] Postavite EPx tako da zapisuje &#8220;Trace&#8221; razinu doga\u0111aja <br \/>\r\n(v.\u2192sl. <a href=\"#EPxServerTraceLog\">EPx server &#8211; Trace log<\/a>)<\/p>\r\n<p>[<strong>A2<\/strong>] Postavite policy EMAgenta za testirane klijente tako da zapisuje &#8220;Trace&#8221; razinu doga\u0111aja <br \/>\r\n(v.\u2192sl. <a href=\"#ERAAgentTraceLog\">EMAgent &#8211; Trace log<\/a>)<\/p>\r\n<p>[<strong>A3<\/strong>] Postavite policy Endpoint za testirane klijente tako da bilje\u017ei dijagnosti\u010dke zapise u dnevnik <br \/>\r\n(v.\u2192sl. <a href=\"#EndpointDiagnosticLog\">Endpoint &#8211; Logging verbosity<\/a>)<\/p>\r\n<p>[<strong>A4<\/strong>] Uklju\u010dite odgovaraju\u0107e napredne dnevnike <br \/>\r\n(v.\u2192sl. <a href=\"#EndpointAdvancedLog\">Endpoint &#8211; Advanced logging<\/a>)<\/p>\r\n<p>[<strong>A5<\/strong>] Pokrenite Wireshark <br \/>\r\n(<a href=\"https:\/\/support.eset.com\/en\/kb6446-how-to-create-wireshark-log\" target=\"_blank\" rel=\"noopener\">https:\/\/support.eset.com\/en\/kb6446-how-to-create-wireshark-log<\/a>)<br \/>\r\nv.\u2192video<br \/>\r\nv.\u2192[B4]<\/p>\r\n<p>[<strong>A5b<\/strong>] Po potrebi ili po dogovoru, uklju\u010dite i Procmon<br \/>\r\n(<a href=\"https:\/\/support.eset.com\/en\/kb6308-using-process-monitor-to-create-log-files\" target=\"_blank\" rel=\"noopener\">https:\/\/support.eset.com\/en\/kb6308-using-process-monitor-to-create-log-files<\/a>)<br \/>\r\nv.\u2192video<br \/>\r\nv.\u2192[<strong>B4b<\/strong>]<\/p>\r\n<p>[<strong>A6<\/strong>] Uklju\u010dite dijagnosti\u010dko <em>logiranje<\/em> i na firewallu, proksiju, .. perimetra<\/p>\r\n<p>[<strong>A7<\/strong>] Zapi\u0161ite to\u010dan datum i vrijeme pokretanja testa<\/p>\r\n<p>[<strong>A8<\/strong>] [v.A9!] Pokrenite proceduru koja dovodi do problema: <br \/>\r\nNpr. po\u0161aljite instalacijski task ili po\u0161aljite task za aktiviranje programa (ili to u\u010dinite na ra\u010dunalu) i sl.<br \/>\r\nAko ne mo\u017eete po \u017eelji &#8220;isprovocirati&#8221; pojavu problema, pri\u010dekajte da se pojavi.<\/p>\r\n<p>[<strong>A9<\/strong>] <strong>Obavezno<\/strong> zapi\u0161ite to\u010dno vrijeme pojave problema! Logovi sadr\u017ee gigabajte teksta i nije mogu\u0107e prona\u0107i gdje se pojavio problem ako ne znamo to\u010dno vrijeme jer i svako potpuno funkcionalno ra\u010dunalo i program imaju tisu\u0107e poruka o pogre\u0161kama, a koje nikako ne utje\u010du na rad<\/p>\r\n<p>[<strong>A10<\/strong>] Isklju\u010dite trace, diagnostic, advanced zapisivanje<\/p>\r\n<p>[<strong>A11<\/strong>] Zaustavite Wireshark <br \/>\r\n(v.\u2192[B4]!)<\/p>\r\n<p>[<strong>A12<\/strong>] Pokrenite naredbu <strong>netstat<\/strong> na ESET Protect serveru, ovisno o operacijskom sustavu:<\/p>\r\n<p>\u00a0\u00a0 [A12A] Linux EPX:<\/p>\r\n<pre>netstat --all --wide --numeric-hosts --numeric-ports --verbose --extend --listening --context<\/pre>\r\n<p>\u00a0\u00a0 [A12B] Windows EPX:<\/p>\r\n<pre>Get-NetUDPEndpoint | select LocalAddress,LocalPort,CreationTime,OwningProcess,@{Name=\"Process\";Expression={(Get-Process -Id $_.OwningProcess).ProcessName}} | Format-Table<\/pre>\r\n<p>&nbsp;<\/p>\r\n<hr \/>\r\n<p><!-- ---------------------------------------------------------------------------------------------------- DETALJNO --><\/p>\r\n<!-- ---------------------------------------------------------------------------------------------------- RAZNO -->\r\n<h2>[B] Slanje logova<\/h2>\r\n<p>[<strong>B1<\/strong>] Prikupite zapise programa ESETLogCollector sa EPx servera<br \/>\r\n(<a href=\"https:\/\/www.nod32.com.hr\/podrska\/kb8275\" target=\"_blank\" rel=\"noopener\">https:\/\/www.nod32.com.hr\/podrska\/kb8275<\/a>)<\/p>\r\n<p>[<strong>B2<\/strong>] Prikupite zapise programa ESETLogCollector sa klijenata<br \/>\r\n(<a href=\"https:\/\/www.nod32.com.hr\/podrska\/kb8275\" target=\"_blank\" rel=\"noopener\">https:\/\/www.nod32.com.hr\/podrska\/kb8275<\/a>)<\/p>\r\n<p>[<strong>B3<\/strong>] Izvezite policyje za EMAgenta i Endpoint <br \/>\r\n(<a href=\"https:\/\/www.youtube.com\/watch?v=lYiQsREEEJw\" target=\"_blank\" rel=\"noopener\">https:\/\/www.youtube.com\/watch?v=lYiQsREEEJw<\/a>)<\/p>\r\n<p>[<strong>B4<\/strong>] Spremite Wireshark zapise u <strong>dva<\/strong> oblika &#8211; .pcapng i .csv <br \/>\r\n(bilo je vi\u0161e slu\u010dajeva da Wireshark nije dobro zatvorio datoteke, pa su testovi &#8220;propali&#8221;)<\/p>\r\n<p>\u00a0\u00a0 [<strong>B4b<\/strong>] Ako ste koristili i Procmon, spremite i te logove<\/p>\r\n<p>[<strong>B5<\/strong>] Spremite zapise firewalla, proksija perimetra<\/p>\r\n<p>[<strong>B6<\/strong>] Dodajte rezultat narebe <code>netstat<\/code> [v.A12]<\/p>\r\n<p>&nbsp;<\/p>\r\n<p>\u2022 Datoteke spremite u ZIP, 7z, RAR, &#8230; ili neki drugi op\u0107eprihva\u0107eni oblik komprimirane arhive s lozinkom<br \/>\r\n\u2022 Ozna\u010dite ih jasno da znamo koji paket pripada kojem ra\u010dunalu<br \/>\r\n\u2022 Prilo\u017eite to\u010dno vrijeme pokretanja testa (i vrijeme pojave problema ako je bio vidljiv)<br \/>\r\n\u2022 Spremite na svoj <em>cloud <\/em>disk ili na na\u0161 FTP (zatra\u017eite podatke ako ve\u0107 unaprijed nismo dogovorili)<br \/>\r\n\u2022 Po\u0161aljite nam link kako bismo preuzeli paket<br \/>\r\n\u2022 Po\u0161aljite nam i lozinku za arhive<\/p>\r\n<p>&nbsp;<\/p>\r\n<hr \/><!-- ---------------------------------------------------------------------------------------------------- SLIKE -->\r\n<h2>Slike<\/h2>\r\n<!-- SLIKA 1 --><!-- SLIKA 2 --><!-- SLIKA 3 -->\r\n<p>\u2022 <a id=\"EPxServerTraceLog\"><\/a>EPx server &#8211; Trace log<\/p>\r\n<p><a style=\"--darkreader-inline-outline: #b30000;\" title=\"\" href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignnone wp-image-8614 size-full\" style=\"--darkreader-inline-outline: #b30000;\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01.png\" alt=\"\" width=\"1500\" height=\"900\" srcset=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01.png 1500w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01-200x120.png 200w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01-250x150.png 250w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01-768x461.png 768w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01-1226x736.png 1226w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-01-675x405.png 675w\" sizes=\"(max-width: 1500px) 100vw, 1500px\" \/><\/a><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>\u2022 <a id=\"ERAAgentTraceLog\"><\/a>EMAgent &#8211; Trace log<\/p>\r\n<p><a title=\"\" href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignnone wp-image-8615 size-full\" style=\"--darkreader-inline-outline: #b30000;\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02.png\" alt=\"\" width=\"1500\" height=\"900\" srcset=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02.png 1500w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02-200x120.png 200w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02-250x150.png 250w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02-768x461.png 768w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02-1226x736.png 1226w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-02-675x405.png 675w\" sizes=\"(max-width: 1500px) 100vw, 1500px\" \/><\/a><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>\u2022 <a id=\"EndpointDiagnosticLog\"><\/a>Endpoint &#8211; Logging verbosity<\/p>\r\n<p><a style=\"--darkreader-inline-outline: #b30000;\" title=\"\" href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignnone wp-image-8616 size-full\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03.png\" alt=\"\" width=\"1500\" height=\"900\" srcset=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03.png 1500w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03-200x120.png 200w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03-250x150.png 250w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03-768x461.png 768w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03-1226x736.png 1226w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/KB8605-03-675x405.png 675w\" sizes=\"(max-width: 1500px) 100vw, 1500px\" \/><\/a><\/p>\r\n<p>&nbsp;<\/p>\r\n<p>\u2022 <a id=\"EndpointAdvancedLog\"><\/a>Endpoint &#8211; Advanced logging<\/p>\r\n<p>Endpoint EN:<\/p>\r\n<p><img decoding=\"async\" width=\"683\" height=\"702\" class=\"alignnone wp-image-10615 size-full\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/Pasted-into-ESET-Protect-brDijagnostika-1.png\" srcset=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/Pasted-into-ESET-Protect-brDijagnostika-1.png 683w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/Pasted-into-ESET-Protect-brDijagnostika-1-195x200.png 195w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/Pasted-into-ESET-Protect-brDijagnostika-1-243x250.png 243w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/Pasted-into-ESET-Protect-brDijagnostika-1-675x694.png 675w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/p>\r\n<!-- ---------------------------------------------------------------------------------------------------- VIDEO -->\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<p>\u2022 EPx arhitektura<\/p>\r\n\r\n<figure id=\"attachment_8643\" aria-describedby=\"caption-attachment-8643\" style=\"width: 1517px\" class=\"wp-caption alignnone\"><a title=\"\" href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"wp-image-8643 size-full\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture.png\" alt=\"ESET Security Management Center ESMC - ESET Protect EPx - Architecture\" width=\"1517\" height=\"843\" srcset=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture.png 1517w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture-200x111.png 200w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture-250x139.png 250w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture-768x427.png 768w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture-1226x681.png 1226w, https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/EPx-EP8-Architecture-675x375.png 675w\" sizes=\"(max-width: 1517px) 100vw, 1517px\" \/><\/a><figcaption id=\"caption-attachment-8643\" class=\"wp-caption-text\">ESET Protect EPx &#8211; Architecture<\/figcaption><\/figure>\r\n\r\n<p>&nbsp;<\/p>\r\n<hr \/><!-- ----------------------------------------------------------------------------------------------------------------------------- -->\r\n<h2>Video<\/h2>\r\n<p>Primjer upotrebe programa ProcMon i WireShark. <br \/>\r\nPrikazuje pripremu okoline za po\u010detak snimanja tek neposredno prije replikacije problema (u ovom slu\u010daju je za primjer odabrana instalacija Agenta):<\/p>\r\n<p>&nbsp;<\/p>\r\n<div style=\"width: 1920px;\" class=\"wp-video\"><!--[if lt IE 9]><script>document.createElement('video');<\/script><![endif]-->\n<video class=\"wp-video-shortcode\" id=\"video-8605-1\" width=\"1920\" height=\"1080\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/1012-opt.mp4?_=1\" \/><a href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/1012-opt.mp4\">https:\/\/www.nod32.com.hr\/podrska\/wp-content\/uploads\/1012-opt.mp4<\/a><\/video><\/div>\r\n<p>.<\/p>\r\n<!-- ---------------------------------------------------------------------------------------------------- SEO -->\r\n<hr \/>\r\n<p class=\"small\">diagnostics dijagnostika xdiagnostics xdijagnostika troubleshooting trblsht xtroubleshooting xtrblsht xepxx epx xepxdiagx epxdiag xtroubleshootingx xprocmon procmon wireshark xwireshark sysinternals xsysinternals emagent xemagent<\/p><div class=\"pdfprnt-buttons pdfprnt-buttons-post pdfprnt-bottom-right\"><a href=\"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/posts\/8605?print=pdf\" class=\"pdfprnt-button pdfprnt-button-pdf\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.nod32.com.hr\/podrska\/wp-content\/plugins\/pdf-print\/images\/pdf.png\" alt=\"image_pdf\" title=\"Download PDF\" \/><\/a><\/div>","protected":false},"excerpt":{"rendered":"Tema Prikupljanje dijagnosti\u010dkih logova za analizu problema u radu sljede\u0107ih dijelova sustava: \u2022 ESET Protect (EPx) server \/ konzola \u2022 EMagent (ESET Management Agent) \u2022&#8230;","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"no","_lmt_disable":"no","footnotes":""},"categories":[3,4,6,13],"tags":[54,81],"class_list":["post-8605","post","type-post","status-publish","format-standard","hentry","category-desktop","category-server","category-epx","category-pogreske","tag-dijagnoza","tag-trblsht","no-wpautop","wpcat-3-id","wpcat-4-id","wpcat-6-id","wpcat-13-id"],"modified_by":"NORT","_links":{"self":[{"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/posts\/8605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/comments?post=8605"}],"version-history":[{"count":2,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/posts\/8605\/revisions"}],"predecessor-version":[{"id":8621,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/posts\/8605\/revisions\/8621"}],"wp:attachment":[{"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/media?parent=8605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/categories?post=8605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nod32.com.hr\/podrska\/wp-json\/wp\/v2\/tags?post=8605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}