Contents
Specific considerations and optimal settings of certain tasks
Certain tasks are subject to specific considerations related to the number of networked devices. This section offers recommendations on the optimal configuration of settings for such tasks.
Device discovery, the data backup task, database maintenance task, and group tasks for updating Kaspersky Endpoint Security are part of the basic functionality of Kaspersky Security Center.
The inventory task is part of the Vulnerability and Patch Management feature and is unavailable if this feature is not activated.
Device discovery frequency
It is not advisable to increase the default frequency of device discovery because this can create an excessive load on domain controllers. Instead, it is recommended to schedule polling at the minimum possible frequency permitted by the needs of your organization. Recommendations for calculating the optimal schedule are provided in the table below.
Device discovery schedule
Number of networked devices |
Recommended device discovery frequency |
---|---|
Less than 10,000 |
Default frequency or less |
10,000 or greater |
Once per day or less |
Administration Server data backup task and database maintenance task
The Administration Server stops working when the following tasks are running:
- Backup of Administration Server data
- Database maintenance
When these tasks are running, the database cannot receive any data.
You may have to reschedule these tasks so that they are not executed at the same time as other Administration Server tasks.
Page topGroup tasks for updating Kaspersky Endpoint Security
If the Administration Server acts as the update source, the recommended schedule option for group update tasks of Kaspersky Endpoint Security 10 and later versions is When new updates are downloaded to the repository with the Use automatically randomized delay for task starts check box selected.
If a local task for downloading updates from Kaspersky servers to the repository is created on each distribution point, periodic scheduling is recommended for the Kaspersky Endpoint Security group update task. The value of the randomization period must be one hour in this case.
Page topSoftware inventory task
You can reduce load on the database while obtaining information about the installed applications. To do this, we recommend that you run an inventory task on reference devices on which a standard set of software is installed.
The number of executable files received by the Administration Server from a single device cannot exceed 150,000. When Kaspersky Security Center reaches this limit, it cannot receive any new files.
Typically, the number of files on a common client device does not exceed 60,000. The number of executable files on a file server can be greater than and even exceed the 150,000 threshold.
Test measurements have shown that the inventory task has the following results on a device running the Windows 7 operating system with Kaspersky Endpoint Security 11 installed and no third-party applications installed:
- With the DLL modules inventory and Script files inventory check boxes cleared: approximately 3000 files.
- With the DLL modules inventory and Script files inventory check boxes selected: from 10,000 to 20,000 files depending on the number of operating system service packs installed.
- With only the Script files inventory check box selected: approximately 10,000 files.