Dell PowerStore 5200T Common Event Enabler 8.9.7.1 Release Notes - Page 6

Issue ID, Functional area, Description, Fixed in version

Page 6 highlights

Issue ID Functional area CEED-1044762 CAVA CEED-1044760 CEPA 1044999 CEPA 1044540 CEE 1040843 1044332 SIEM CEE 1025659 CTA/CEMA 953010 CAVA 926683 894483 CEPA/VCAPS CAVA 833155 CAVA 815068 CEPA Description CEE installation fails on machines with Symantec Endpoint Protection installed. Users who installed CEE version 8.7.8.1 configured for use with the CEPA facility may see a failure of CEE to validate partner applications. The platform shows CEE in a state of not being able to find the partner application. Resolution: Install CEE version 8.7.8.2 onto all CEE machines that are running CEE version 8.7.8.1. A CEE/CEPA memory leak issue occurred while using CEE version 8.7.0.0. The CEE code was updated to call functions that free up memory to stop the leaking. On Linux systems, incoming fileSid and userSid messages are correct when logged by CEE. However, digits are mixed, swapped, and incorrectly parsed when the message leaves CEE. The CEE code's decoding algorithm for Linux systems was updated to extract the correct SID string format. The CEE code was updated to include provisioning support for Stealthbits. CEE Monitor Service did not start on Windows 2016 servers. The CEE code was updated to correct exceptions that occurred while reading variables during startup. Under certain CTA archive/recall loads, CEMA encryption/decryption calls occasionally failed. The CEMA code was modified for calls to third-party libraries (openssl, rsa eDPM). Overall latency set between when a Microsoft Defender scan ends and the Defender remediation actions begin is greater than the current CEE/CAVA remediation window. The CEE code was updated to fix the latency timing. The CEE code was updated to add new partner Intrafind search/index application credentials to CEE as a VCAPS application subscriber. Symantec changed the XML layout of three configuration files that CAVA uses to locate PE configuration information. The CAVA code was updated to correctly read the new Symantec layout and translate the PE configuration information. Messages exchanged between CEE and VNX/Dell Unity systems showed a "Network Associates" label for the McAfee AV product. It should be "McAfee" instead. The CAVA code for VNX and Dell Unity systems was updated to show "McAfee AV" as the antivirus engine name. CEPA events only allow filtering by NetBios name, and not by Fully Qualified Domain Name (FQDN). The CEPA code for partner event filtering was enhanced to include filtering by event source FQDN. Fixed in version 8.8.1.0 8.7.8.2 8.7.8.1 8.7.8.1 8.7.7.0 8.7.7.0 8.7.5.0 8.5.1.0 8.4.2.0 8.4.2.0 8.2.0.0 8.2.0.0 6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12

6
Issue ID
Functional area
Description
Fixed in version
CEED-1044762
CAVA
CEE installation fails on machines with Symantec
Endpoint Protection installed.
8.8.1.0
CEED-1044760
CEPA
Users who installed CEE version 8.7.8.1 configured
for use with the CEPA facility may see a failure of
CEE to validate partner applications. The platform
shows CEE in a state of not being able to find the
partner application.
Resolution: Install CEE version 8.7.8.2
onto all CEE
machines that are running CEE version 8.7.8.1.
8.7.8.2
1044999
CEPA
A CEE/CEPA memory leak issue occurred while
using CEE version 8.7.0.0. The CEE code was
updated to call functions that free up memory to
stop the leaking.
8.7.8.1
1044540
CEE
On Linux systems, incoming fileSid and userSid
messages are correct when logged by CEE.
However, digits are mixed, swapped, and incorrectly
parsed when the message leaves CEE. The CEE
code’s decoding algorithm for Linux systems was
updated to extract the correct SID string format.
8.7.8.1
1040843
SIEM
The CEE code was updated to include provisioning
support for Stealthbits.
8.7.7.0
1044332
CEE
CEE Monitor Service did not start on Windows 2016
servers. The CEE code was updated to correct
exceptions that occurred while reading variables
during startup.
8.7.7.0
1025659
CTA/CEMA
Under certain CTA archive/recall loads, CEMA
encryption/decryption calls occasionally failed. The
CEMA code was modified for calls to third-party
libraries (openssl, rsa eDPM).
8.7.5.0
953010
CAVA
Overall latency set between when a Microsoft
Defender scan ends and the Defender remediation
actions begin is greater than the current CEE/CAVA
remediation window. The CEE code was updated to
fix the latency timing.
8.5.1.0
926683
CEPA/VCAPS
The CEE code was updated to add new partner
Intrafind search/index application credentials to CEE
as a VCAPS application subscriber.
8.4.2.0
894483
CAVA
Symantec changed the XML layout of three
configuration files that CAVA uses to locate PE
configuration information. The CAVA code was
updated to correctly read the new Symantec layout
and translate the PE configuration information.
8.4.2.0
833155
CAVA
Messages exchanged between CEE and VNX/Dell
Unity systems showed a "Network Associates" label
for the McAfee AV product. It should be "McAfee"
instead. The CAVA code for VNX and Dell Unity
systems was updated to show “McAfee AV” as the
antivirus engine name.
8.2.0.0
815068
CEPA
CEPA events only allow filtering by NetBios name,
and not by Fully Qualified Domain Name (FQDN).
The CEPA code for partner event filtering was
enhanced to include filtering by event source FQDN.
8.2.0.0