Hi,
I am struggling a little bit with evidence in DLP. I have another question posted, but please disregard my issues with that as I have a temporary workaround for the purposes of testing.
Evidence is being reported back and being saved on the servers c:\evidence folder. However, within the monitor, I cannot decrypt the selected event as the option is greyed out. What could be causing this? I am a global administrator so this shouldn't be a permissions issue?
http://i39.tinypic.com/vgk5g1.png>
As a side note, if the evidence was being stored on a seperate server (that wasn't running EPO or hosting DLP or it's database), how would I go about decrypting the evidence?
Many thanks
I see you posted a lot of questions lately - maybe it would be good for you to engage your support team and get some help setting up DLP? There's only so much help you'll get within the Community, as we are all volunteers here, not professional support?
Point taken, thanks anyway
np - I am not an expert, but I thought that the evidence folder had to be a UNC path? It's a long time since I looked at this though.
With the event highlighted the evidence link will be on the right-hand side at the end of the pane. Double-click the evidence to open it. Now if that fails you can right-click and choose 'copy'. Paste into notepad and the data related to that evidence file will be revealed. Try and navigate to the link you just pasted and any problems accessing the file will be apparent.
Best Regards
Chris Norris, CISSP
McAfee Tier III Support Engineer
Data Loss Prevention Endpoint
DLPE Troubleshooting Tree: https://kc.mcafee.com/corporate/index?page=content&id=PD23517
McAfee website: www.mcafee.com
McAfee Corporate Online Support (Service portal): http://www.mcafee.com/us/enterprise/support/index.html
Chris, very helpful indeed, thankyou. It has also answered my question of how to 'import' evidence from another location.
Are you trying to import data from evidence or decrypt to read the contents? Are you able to decrypt from DLP Prevent incident or better stil explain your setup. I have similar issues and was able to resolve by 1. making sure the share evidence is set in server configuration and client settings, 2. test the connection and make sure it all correctly connected, also 3. check the permission on the evidence share folder and make sure the ePO computer account has RW access from security group settings.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA