Trend ServerProtect Real Time Scan kills Performance

I've just virtualized a Windows 2003/Citrix Presentation Server 4.5 server on a host of vSphere with a NetApp FAS2020 using NAS as the data store where the virtual machine is stored.  There is no other guests of the VM on the host for the moment and the NetApp is not still used for other purposes (i.e. nothing should be taxing the material).  I found that ServerProtect V5.58 time real scan running on the Citrix server limits the CPU at a constant 100% once about 8 users are connected.  If I disable the real-time scanning, everything goes back to normal.

Clearly, I must be able to protect users from malicious software Citrix sessions.  What is the best way to achieve this with Citrix/Terminal Server VMware?

Someone at - it a version more recent ServerProtect or even OfficeScan running successfully within Citrix/Terminal Services hosted on VMware?

Thank you

D.

Hello

Moved to the Security Forum.

Reinstall the trend after a P2V could help but maybe not.

Trend also made programs specifically for virtualization and vSphere that will do A / V of the analyses using the API that will not also drastically affect performance vStorage, it's something to look into. Maybe but not 'real time' will allow better overall analysis.

Best regards
Edward L. Haletky VMware communities user moderator, VMware vExpert 2009, 2010

Now available: url = http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security'VMware vSphere (TM) and Virtual Infrastructure Security' [/ URL]

Also available url = http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"VMWare ESX Server in the enterprise" [url]

Blogs: url = http://www.virtualizationpractice.comvirtualization practice [/ URL] | URL = http://www.astroarch.com/blog Blue Gears [url] | URL = http://itknowledgeexchange.techtarget.com/virtualization-pro/ TechTarget [url] | URL = http://www.networkworld.com/community/haletky Global network [url]

Podcast: url = http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcastvirtualization security Table round Podcast [url] | Twitter: url = http://www.twitter.com/TexiwillTexiwll [/ URL]

Tags: VMware

Similar Questions

  • can not turn on real-time scanning 0x8000705b4 error code

    got fed up with Mcafee so I removed the product with the programs and features and then used their cleaning cleaning tool Development than anything flying over. When I try to turn on real-time scanning, I get the 0x8000705b4 error code.  The defender service is running.  I have windows 8.

    I decided to solve the problem by setting another disorder, that I'd been procrastinating. I've migrated my operating system on an SSD and could not be upgraded to win 8.1. A little research revealed that I was not the only 1 with this disorder.  In any case, a clean install of win 8.0 followed to upgrade to win the 8.1 and the problem disappeared.  Thanks for your help.

  • Real-time scanning and firewall disabled

    Every time I turn off my pc, the sacnning in real-time and the firewall are disable... and it happed after I purchsed online McFee, I used to have Panda Antivirus for Netbooks and used to work in perfect!

    I will never againg buy McAfee products, I told my two sister not to buy any product from McAfee for their pc... and I have already said that most of my friends not to buy no matter what McAfee Antivirus...

    .. .it really sucks...

    I recommend that you uninstall McAfee using the special removal tool: http://www.softpedia.com/get/Tweak/Uninstallers/McAfee-Consumer-Product-Removal-Tool.shtml (not just uninstall because it works well and you will have problems with the system itself, as well as with the installation of other products).  If you just bought it, it may still be in some kind of trial period and you may be able to get a refund if you have already paid for it (you should check with them on that).  Explain your problems, if necessary, and that you intend to report on blogs and everywhere you can and they may decide to make an exception if at first, they refuse to allow the return.

    Once done, reboot and you should now be able to re - activate the Windows Firewall. http://Windows.Microsoft.com/en-us/Windows-Vista/turn-Windows-Firewall-on-or-off Check to ensure that the parameters are still accurate that McAfee could change their.  If this isn't the case, after return and we will try to understand how they disabled so we can reactivate if the normal process does not work.

    Then, you need something to replace McAfee for AV / AM fine.  I recommend Microsoft Security Essentials for free at:http://www.softpedia.com/progDownload/Microsoft-Security-Essentials-Download-131683.html for analysis in real time on the daily basis and periodic analyses of rapid or complete.  I also suggest the free Malwarebytes to:http://www.malwarebytes.org/mbam.php don't not running constantly, but in order to update and do a full scan every few weeks or just to catch whatever it is, MSE could miss.  These two products are much better than McAfee and don't cause you problems that you had to deal with.  Here's what I use and I had no problem (and no infections that were not intercepted and completely removed by one or the other).  Either way, I used myself the Panda for several years before moving to the MSE and I have nothing bad to say about them - their product is very good - but why pay for something when there are free alternatives that are almost everything as good (maybe even better)?

    I hope this helps.

    Good luck.

    P.S. Be grateful it is McAfee and Norton not - so you could be even greater problems.

    Lorien - MCSA/MCSE/network + / has + - if this post solves your problem, please click the 'Mark as answer' or 'Useful' button at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • Weird scenario - full table on TEST db scan kills performance in Production

    Hello
    We have a battery of Linux servers connected to HP XP as SAN storage.
    Observe behavior strange since last week... every time the table sys.aud$ is full-table-analysed in the TEST database of someother in someother server (also connected to the same SAN), the number of Sessions active in the PROD shot thru the roof and demand grinds online banking services to stop.

    HP storage engineers came and open consoles and showed graphs of performance in mosaic... and it didn't break a sweat with the exception of a peak in 15 sec during the FTS in TEST. They swore on their first wives that the storage is not the reason for it.

    We are also engaging Oracle Support on this, but Oracle Support is not very creative to combat this situation and just point to the problem of the AWR reports storage (it then, surprise!)

    Everyone has never experienced a similar situation, please let us know of your resolution.
    5.6 Linux, 11.2.0.3, using ASM (Infrastructure grid version 11.2.0.3)

    Thank you

    932957 wrote:
    Thanks Mark, EXACTLY during the problem, without CPU spikes... ASM iostat shows an increased activity and vmstat BONE ' watch the block-ed queue springs (2nd column below):

    What is the table$ aud, what kind of I/O calls are made to read.

    The 'in principle' the explanation is simple - research is so great and works like a large number of (relatively small) e/s asynchronous requests that it floods the I/O queue to the San. ANY sharing of a SAN, by I/O intensive applications is likely to result in a request to slow down during I/O points by others.

    If your banking application is running 3-layer with connection pooling in the middle tier, it is probably configured with dynamic connections pools, and when the database response time increase (due to I/O test) the middle layer is short of free connections and creates a few more - who are probably slow to start because the I/O response time is poor , therefore the intermediate creates others...

    It was more weird when this problem arose at the beginning... every 30 minutes, the prod will boost Active Sessions and for the life of us, we could not understand... it took days to understand metric Grid Control "FAILED CONNECTION ATTEMPTS" runs a full scan on sys.aud$ in the TEST database every 30 minutes and then whenever we did a COUNT (*) SELECT SYS. AUD$ test, we were able to reproduce it.

    Not one of the best bits of implementation ;) Oracle http://jonathanlewis.wordpress.com/2010/04/05/failed-login/

    Concerning
    Jonathan Lewis

  • Real-time performance only a single host

    I have VC 4.1.0 build 345043 with 3 hosts esx 4.1.0.  Two hosts are build 348481 others I have patched 2 days ago now show 381591. The patched, updated VC performance statistics window in real time. I can see old week data, but the data stops when I patched. If I ask for the last day, I get Performance data na. The other is home again all the data of the report. I've read other issues, but the problem made all hosts. My time is on all hosts and VC. I restarted the affected host. I scan the host that it shows all patched. What's left to try?

    I know you rebooted the host, but one last thing to try is to restart the management agents... If you have SSH access or console, you can issue the below commands.

    first:

    service vmware-vpxa restart
    

    If this does not help then

    service mgmt-vmware restart
    
  • Gaps in real-time performance dashboards

    Does anyone know of a possible cause of the gaps appearing regularly in the performance tables when they are set to 'real time '?

    Others have asked similar questions, usually after an upgrade or for older versions.  However, I recently built a system.  We organize several hosts ESXi 3.5 (build 153875) in VirtualCenter 2.5 (build 174768).  A couple of my guests appear very strange performance data. Not only we get gaps in the graphics... we see also the first parcel back with equal values "s/o".  Has anyone seen this before and/or solved this annoying problem?

    You can try to restart the console screen management officers.

  • Able user to zoom in/out the image in real time the performance of façade?

    Well I have searched this and have developed empty. What I would do, is to have a picture of a diagram on the front panel and during execution of the VI user can somehow zoom in/out the image in real time.

    I know there is something that is called Zoomfactor that you instantiate a way in the block diagram, but that seems to zoom in on a picture of race prior to the program. The zoom is not in real time. There is no possibility of real user to zoom in/out with free will, using the Zoomfactor I see. (Sorry I forgot display name of the service). And I saw messages by a man named George Zou that seems to come with a VI which is closest to what I want, but I pulled the VI site seems not compatible with my computer (my rig is under XP with Labview 2013 currently). So, I was wondering if someone else had found other answers appropriate to my specifications?

    Use a structure of the event to change magnification during execution.

    You can even program your own shortcuts to the structure of the event, for example if the user clicks on a particular point on the picture and you read this coordinate on, and you zoom way at this point remains in the Center... There are many options to play with...

  • The performance improvement chart real time

    I'm working on a simple graph in real time. The data is queried every 50ms, and each survey results in a line one pixel wide, height in pixels (data_point) . The chart scroll such as new data is located on the right, and the oldest values ends up by falling from the left.

    In other words, pretty basic.

    My solution is embarassingly brute-force, in what I just use theMC.graphics.clear () and a loop of lineTo()s for each graphic update. If this appears correctly (and I can control the refresh rate to mitigate CPU burn), it should be painfully obvious why I want to get away from this method.

    I have to scroll or pan the a full graphic pixel to the left (and remove the line to the left) and then just pull a new line on the right, but I don't know where to start. Assuming that such a thing is possible in AS3, someone would be kind enough to point me in the right direction?

    This can be done a few ways.

    First class graphics.

    its safe to assume that you draw with the graphics removed the displayObject?

    Otherwise, you make several updates in the loop.

    Remove the displayList drawing while pulling all parcels.

    Then, BitmapData.

    You can use scroll(1,y) to move the image to the left.  In addition, by using bitmap data, you can lock the bitmapData to limit the refreshment of a given area.

    workign with the image bitmap information is easier to use when drawing...   Of course, this requires a little more math you can't use just line with bitmapData.

    But you can use a matrix to rotate a line at 90 degrees and increase in length.

  • Windows Essentials program running "Real-time Protection"... the mouse cursor turns into hourglass several times per second...

    I have disable real-time protection it stops on and off an hourglass toggleing... its annoying... How to stop to turn to an hourglass without disabling protection... it doesn't seem to be a problem of performance... but it is visually annoying... Please and thank you for your comments.

    I had just installed Microsoft Essentials... before uninstalling software anti-virus TrenMicro expired... maybe Detailer left some files on my system after uninstall?

    Hello

    This problem normally occurs when there are files that are infected by viruses.

    Method 1:

    Run a scan antivirus on your computer.

    www.Microsoft.com/Security/Scanner

     
    Note: If infections are detected during the scan, there is a risk of data loss because infected files will be deleted.

    Method 2:

    You also try to run the uninstaller to complete tool to remove traces of antivirus Trend.

    http://eSupport.trendmicro.com/solution/en-us/1056551.aspx

    Check the issue.

    Method 3: Clean boot

    If the problem persists, you can place the computer in a clean boot.

    Put the computer in a State of boot is a way to know which application is causing this problem.

    To help resolve the error and other messages, you can start Windows by using a minimal set of drivers and startup programs. This type of boot is known as a "clean boot". A clean boot helps eliminate software conflicts.

    Put your boot system helps determine if third-party applications or startup items are causing the problem. If so, you need to maybe contact the manufacturer of the program for updates or uninstall and reinstall the program.

    Step 1: Follow the steps in the link below to do the same thing:

    How to configure Windows XP to start in a "clean boot" State

    Note: After troubleshooting, be sure to set the computer to start as usual as shown here:

    Step 2: To configure Windows to use a Normal startup state

    After you have used the boot is a way to solve your problem, you can follow these steps to configure Windows XP to start normally.

    a. Click Start and then click Run.

    b. type msconfig and click OK. The System Configuration Utility dialog box appears.

    c. click on the general tab, click Normal Startup - load all services and device drivers and then click OK.

    d. When you are prompted, click on restart to restart the computer.

    Hope this information helps. Response with status so that we can help you.

  • MacAfee says real-time internet security disabled during access via Firefox.

    Although the Green OK of MacAfee sign illuminates when accessing e-mail in xplornet.ca via Firefox (my default), a message tells me that MacAfee real-time protection is disabled. By clicking on the button 'Activate' returns me seconds to red alert "off."

    This has happened

    Each time Firefox opened

    Hello Mark.

    Well maybe not related to your problem, I have to remind you that the version of Firefox you are using right now has been deleted and is no longer supported. In addition, he has known unpatched bugs and security problems. I invite you to upgrade to the latest version of Firefox, for maximum security, stability, performance and ease of use. You can get it for free, as always, to getfirefox.com.

    What about your problems, you must contact McAfee support.

  • Analyzers of vector signals OR, in real time of tektronix and tests EMC spectrum analyzers

    Normal
    0

    21

    fake
    fake
    fake

    PT - BR
    X NONE
    X NONE

    MicrosoftInternetExplorer4

    / * Style definitions * /.
    table. MsoNormalTable
    {mso-style-name: "Table normal";}
    MSO-knew-rowband-size: 0;
    MSO-knew-colband-size: 0;
    MSO-style - noshow:yes;
    MSO-style-priority: 99;
    MSO-style - qformat:yes;
    "mso-style-parent:" ";" "
    MSO-padding-alt: 0 cm 0 cm 5.4pt 5.4pt;
    MSO-para-margin-top: 0 cm;
    MSO-para-margin-right: 0 cm;
    MSO-para-margin-bottom: 10.0pt;
    MSO-para-margin-left: 0 cm;
    line-height: 115%;
    MSO-pagination: widow-orphan;
    font-size: 11.0pt;
    font family: 'Calibri', 'sans-serif ';
    MSO-ascii-font-family: Calibri;
    MSO-ascii-theme-make: minor-latin;
    MSO-hansi-font-family: Calibri;
    MSO-hansi-theme-make: minor-latin;
    mso-fareast-language: EN-US ;}

    1. how to work if vector performance of or
    Analyzers of signals compare to Tektronix real-time spectrum analyzers?

    2 can you emulate Tektronix FFT
    processing overlapping?

    3. is it possible to use vector of NOR
    Analyzers of signals of compliance EMC and/or test preconformite? Is there some
    companies use it successfully? Need a special or custom software?

    Thank you

    Hi emc2006

    I'll answer your questions separated by your topics:

    1 - What is the factor that you want to compare between these two products? In the link below, you will find the performance of the NI PXI-5660 RF Signal Analyzer system.
    2. you can develop this feature of programming in software Application development, i.e. of LabVIEW.
    3. Yes, NI´s vector signal Analyzer could run preconformite or EMC compliance analyses. In the same link below, you will find in the subdivision of Applications.

    http://zone.NI.com/DevZone/CDA/tut/p/ID/4298

    Concerning

    Napoleao
    Application engineering
    National Instruments

  • Continuous data acquisition and real-time analysis

    Hi all

    It is a VI for the continuous acquisition of an ECG signal. As far as I understand that the analog read DAQmx VI must be placed inside a while loop so it can acquire the data permanently, I need perform filtering and analysis of the wave in real time. How I implemented the block schema means that data stays int the while loop, and AFAIK the data will be transferred on through the tunnels of data once the loop ends the execution, it clearly isn't real-time data processing.

    The only way I can think to fixing this problem is by placing another loop that covers the screw scene filtering and using some sort of registeing shift to transmit the data in the second while loop. My question is whether or not it would introduce some sort of delay, and weather or not it would be supposed to be the treatment in real time. Wouldn't be better to place all the screws (aquicition and filtering) inside a while loop? or it is a bad programming practice. Other features I need to do is back up the data I na file, but only when the user wants to do.

    Any advice would be appreciated.

    You have two options:

    • A. as you said, you can place the code inside your current while loop to perform the treatment.  If you're smart, you won't need to put one another while loop inside your existing (nested loops).  But it totally depends on the type of treatment that you do.

    • B. create a second parallel loop to perform the treatment.  This would be separate processes to ensure that the treatment is not obstacle to your purchase.  For more information, see here .

    Your choice really depends on the transformation that you plan to perform.  If it's much the processor, this could introduce delays as you said.

    I would recommend that you start at any place in the first loop and see if your DAQ buffer overruns (you can monitor the rear of the buffer during operation).  If so, you should decouple the process in separate loops.

    In what concerns or not ' it would be considered as real time processing ' is a trick question.  Most of the people on these forums say that your system is NEVER in real time because you're using a desktop PC to perform processing (note: I guess it's the code that runs on a laptop or desktop?).  It is not a deterministic systemand your data is already "old" by the time wherever he leaves your DAQ buffer.  But the answer to your question really depends on how you define "real time processing".  Many lay it will set as the treatment of 'live' data... but what is "actual data"?

  • Convert a desktop PC to a target of VeriStand real-time

    Hello

    I have to convert a desktop PC to a target of VeriStand real-time.

    What are the PC requirements to convert the PC to a target of VeriStand real-time? They are the same as the requirements to convert a PC to a time target real LabVIEW?

    http://www.NI.com/white-paper/8239/en

    What is the procedure to install the engine time real Veristand to the RT PC? Is this the same as the procedure to install LabVIEW Real-time to a RT PC?

    http://www.NI.com/white-paper/2733/en/#toc4

    And what I have to install engine LabVIEW Real-time before installing engine VeriStand real-time?

    Last question: can I install the engine time real VeriStand on a PXI controller - 8115 Windows by creating a dual boot on my own? (PXI-8115 can be purchased with Windows or LabVIEW RT or the dual boot Windows/LabVIEW RT.)

    Thanks for your replies.

    Best regards.

    David

    (1) Yes
    2) kind of. Neither veristand engine is just an application that runs on the RT or windows. So once you follow this guide to make the target RT desktop computer you can install the NIVS motor application through MAX
    (3) Yes. Remember that the nivs engine can run on windows or RT so if the 8115 runs windows, you can run NIVS targeted toward you. If the 8115 runs RT you would need a separate windows PC and target the 8115 from that. Or you could put the hypervisor (if the 8115 supports) to simultaneously run windows and RT on the 8115 and so to run the client side NIVS windows targeting the engine on the side of the RT veristand... About a penalty of 50% of the performance

  • Trying to update channels in real time while controlling the Agilent 34970

    Hi all

    I got Aussie help on these forums and I hope that someone will be able to point me in the right direction with this problem. I'm still fairly new to LabVIEW please bear with me.

    I work with the LabVIEW driver for the Agilent 34970 connected on a GPIB-ENET 100/1000. The device was detected and works very well. The reason why I am writing today, what I'm trying to update the list channels in real-time. Currently I need to stop the whole process in order to modify the list of channels, but due to the nature of the tests we will occur, it is important that I can add more channels I want without interrupting the ongoing trials.

    I searched the forums and tried to change control of chain of channel for "Update of the value while typing" and "limit to the only line." The motivation behind the change of the latter was so that I could change the channel list and use the ENTER key to run. I also tried to create a while loop with shift registers but construction ws so clumsy that it does no more.

    I am sure that the change must take place as soon as the control of the chain, but is not certain since the pint is so he can reset which channels to scan and which appears lower in the VI. I have attached the VI I work with; It is a slightly modified version only Advanced Scan example of the driver.

    Thank you in advance,

    Yusif

    You might have added a registry to shift, but you're not actually compare anything. You compare the value of the control to the value of the data coming from the shift register to see if it has changed. If so, change the scan list.

    If you need to have a delay after you change the scan list, then you must add the delay within the business structure that calls the VI to reconfigure the scan list. You can use the late VI period causes the delay occur after you set up the analysis using the wires of the error to force the order of execution.

    P.S. Your naming scheme for screw means that you probably use a source code control system. If so, you would be well served by taking the time to discover the source control systems and installing a. It is very easy, and he has had several discussions in the LabVIEW forum on recommendations of source code control systems.

  • Why won't my installer in real-time?

    I'm using labview 8.51.  I have many addons on my machine including DSC Vision FPGA and RT.  I have an application which usis daq mx and the imaq and imaq-dx (no vision saw.  I added 8.51 engine performance, NI-Imaq, NOR-Imaq-dx, Max 4.1 and Daqmx8.7.  I run the installer, but he still wants the disk in real time.  This application uses no screws RT and should not waqnt this disc.  What triggers this action and how I can avoid it.  I have had this problem several times and can't seem to find one alternative that the shipping of my separate installers (I hate this solution).

    Hi Paul,.

    Just to clarify, you have no need to manually copy the CD on the hard drive, like the LV application builder automatically only record it is necessary if you check the option "cache" during the construction of the installer. Please see this thread for more information on why Builder app works this way: link

    Kind regards

    -Wes / NOR

Maybe you are looking for

  • How to automatically send an sms to the team?

    I would like to know if there is a way (setting) or an application that can automatically send an sms (txt) to my team?

  • 970cxi - peer peer windows 8.1 network

    just bought a new windows 8.1 and added to our network of peer to peer. Another machine has this deskjet attached - when I try and connect via the network I just get - no driver not found. If I connect directly to that machine, windows update detects

  • Z10 Wi - fi BlackBerry

    Hello! Just turned on my new phone and do the installation on the phone instructions. Setup cannot continue until I choose a wi - fi network, but there is no wireless connection in my house.

  • problem with the windows Task Manager.

    Hello.i uses windows 7 64 bit and I have a problem with my windows task manager.i am still able to use the windows task manager but when it appears, the tab all lack .it s display only a program this running.i hope you can help solve this problem.tha

  • Device behind a Firewall other, ASA VPN

    I have a client who wants to put their VPN / behind the ASA ASA main connected to the Internet.  Both devices have an inside leg for the internal network, but the ASA VPN connects directly to the Internet ASA. Topology: Outisde FW: Internet transfer