<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: virus scan storm in Array Performance and Data Protection</title>
    <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986288#M1086</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the 2.2 code and higher will prevent random scans and write from flushing the cache. If your not on those code levels, you should upgrade.&amp;nbsp; The other way to work around this is to write a script to disable cache on the effected volume during the scan, and then turn it back on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Feb 2016 17:17:49 GMT</pubDate>
    <dc:creator>rugby0134</dc:creator>
    <dc:date>2016-02-16T17:17:49Z</dc:date>
    <item>
      <title>virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986287#M1085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I received a Cache under-provisioned error. &lt;/P&gt;&lt;P&gt;Happened during a scheduled anti-virus scan.&lt;/P&gt;&lt;P&gt;I guess you can call it a virus scan storm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where to go from here? Any suggestions ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2016 17:06:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986287#M1085</guid>
      <dc:creator>jkim13</dc:creator>
      <dc:date>2016-02-16T17:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986288#M1086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the 2.2 code and higher will prevent random scans and write from flushing the cache. If your not on those code levels, you should upgrade.&amp;nbsp; The other way to work around this is to write a script to disable cache on the effected volume during the scan, and then turn it back on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2016 17:17:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986288#M1086</guid>
      <dc:creator>rugby0134</dc:creator>
      <dc:date>2016-02-16T17:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986289#M1087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are on 2.3.9.2. code. So we are already on that code level. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2016 18:06:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986289#M1087</guid>
      <dc:creator>jkim13</dc:creator>
      <dc:date>2016-02-16T18:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986290#M1088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Move away from traditional AV scanning, protect your endpoints and use AV scanning at the hypervisor level is much more efficient and solves your problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IO storms during scans are a very common and there is no solution other than the above, you can mitigate the effect by offsetting the scans. NOTE: this offsetting of the times is something you should also apply to the application of WSUS updates!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2016 10:00:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986290#M1088</guid>
      <dc:creator>chris24</dc:creator>
      <dc:date>2016-02-24T10:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986291#M1089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using Symantec Endpoint Protection, I would look for a feature called Insight Cache.&amp;nbsp; If you're forced (i.e. compliance) to do 'absolute' FULL scans on every machine every day or week, and your AV scan policies or endpoint groups aren't staggered, I would highly recommend an antivirus solution that compares file hashes on the scanned target, instead of actually scanning each and every file.&amp;nbsp; You might not eliminate all of the load, but it definitely was noticeable for us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 17:27:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986291#M1089</guid>
      <dc:creator>alex_goltz</dc:creator>
      <dc:date>2016-02-26T17:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: virus scan storm</title>
      <link>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986292#M1090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have Symantec because someone finds it add's value.&amp;nbsp; I could argue that point but I dont.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead we run the latest version 12.1.6 (?) the version that allows for a "light" client with drastically reduced definition file sizes and updates.&amp;nbsp; The down side is that it only has definitions for the latest malware.&amp;nbsp; We also have turned off scheduled scans.&amp;nbsp; We only scan on file modification, which for 99% of the files on a VM are never touched after they arrive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have lot's of other layers in the environment, PaloAlto, FireEye...etc which actually catch/block stuff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also run WSUS updates in the wee hours of the morning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2016 02:56:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/array-performance-and-data/virus-scan-storm/m-p/6986292#M1090</guid>
      <dc:creator>lindy37</dc:creator>
      <dc:date>2016-03-01T02:56:33Z</dc:date>
    </item>
  </channel>
</rss>

