I am struggling a little bit with evidence in DLP. I have another question posted, but please disregard my issues with that as I have a temporary workaround for the purposes of testing.
Evidence is being reported back and being saved on the servers c:\evidence folder. However, within the monitor, I cannot decrypt the selected event as the option is greyed out. What could be causing this? I am a global administrator so this shouldn't be a permissions issue?
As a side note, if the evidence was being stored on a seperate server (that wasn't running EPO or hosting DLP or it's database), how would I go about decrypting the evidence?
I see you posted a lot of questions lately - maybe it would be good for you to engage your support team and get some help setting up DLP? There's only so much help you'll get within the Community, as we are all volunteers here, not professional support?
np - I am not an expert, but I thought that the evidence folder had to be a UNC path? It's a long time since I looked at this though.
With the event highlighted the evidence link will be on the right-hand side at the end of the pane. Double-click the evidence to open it. Now if that fails you can right-click and choose 'copy'. Paste into notepad and the data related to that evidence file will be revealed. Try and navigate to the link you just pasted and any problems accessing the file will be apparent.
Chris Norris, CISSP
McAfee Tier III Support Engineer
Data Loss Prevention Endpoint
DLPE Troubleshooting Tree: https://kc.mcafee.com/corporate/index?page=content&id=PD23517
McAfee website: www.mcafee.com
McAfee Corporate Online Support (Service portal): http://www.mcafee.com/us/enterprise/support/index.html