We’ve been seeing some odd behavior, and I am wondering if any of you have seen similar. We have had 100-ish systems that we were seeing the last report time that was out further that we wanted it to be (these are remote employees), and at first assumed it was an issue with them slacking on the job LOL! When we started digging into these systems we are seeing the BESClient process running, but it is like no one is home.
Checking logs shows the last entry on the last day it reported in, but then nothing. It’s like the process hung, as nothing in the logs indicate issue with it not being able to send reports or anything related to finding relays, etc. It’s odd… we have to kill the BESClient process and it restarts and works fine - checks in, sends reports, and can fixlets on them again.
These are all windows desktop systems, and we keep them up to date with patches and versions. I have no turned on any debugging on any client, as restarting the client fixes the issue and it has been very random. I’ve had to MacGuyver a “fix” to use Bigfix’s api in powershell to get systems who are offline, then use that data via our antivirus’ API and run kill commands on the BESClient process… it works, but not sure why the client is behaving this way. Any ideas or reports of this happening to you all?