cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

DLP Incidents not reflecting in incident manager

Jump to solution

Hello Team,

We were testing Data Protection rules on our test machines until yesterday everything seems to be working fine. Now what is happening is rules are triggering as expected and events are also getting generated in the client DLP 11 console but the same events are not reflecting in incident manager earlier we were able to view the incidents in incident manager.

Thanks in advance

1 Solution

Accepted Solutions
McAfee Employee DLP_RS
McAfee Employee
Report Inappropriate Content
Message 5 of 6

Re: DLP Incidents not reflecting in incident manager

Jump to solution

We should be seeing the incident each time it has been triggered. Please check for the following.

1. Are you able to trigger the rule now?

2. Once again verify the places(including Debug and rest of the folders on ePO and client) if the event is there? Also are you seeing reporting on ePO Dashboard for rest of the point products like MA|VSE|ENS?

3. What about the other rules? Are they triggering? Also check Database size?

I would suggest to log a service request for detailed troubleshooting by McAfee Technical Support. 

May be case of corrupt DLP extension and need to either upgrade to a higher one Or remove and reinstall it? 

5 Replies
McAfee Employee DLP_RS
McAfee Employee
Report Inappropriate Content
Message 2 of 6

Re: DLP Incidents not reflecting in incident manager

Jump to solution

Suggestions--

1. Please check if under Eventparser.log if there are any errors while processing the events. Location

C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Logs Or may vary if you have installed ePO in a different drive.

2. Are there any unprocessed events in ePO server- Also any other point product is impacted?

C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Events

3. Check the Database size if it is not Full.

4. Also verify if events are not stuck at client machine-

C:\ProgramData\McAfee\Agent\AgentEvents

5. Ensure that Eventparser service is running.

 

Re: DLP Incidents not reflecting in incident manager

Jump to solution

Please find the below observation as per your instruction.

  1. Are there any unprocessed events in ePO server- Also any other point product is impacted?
    C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Events

          >>>>> I dont think there is any unprocessed events, I might be wrong here but I dont see any                             events there
                    The only thing is see there is the two others folder namely 1)Debug 2)Unknown

     2. Please check if under Eventparser.log if there are any errors while processing the events. Location
         C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Logs Or may vary if you have installed                 ePO in a different drive.

          >>>>>>I dont think there is an error with processing here Please find the below example
                      HOSTDLPEVENT Processed event successfully. Time elapsed: (in ms): 31

   4.  Also verify if events are not stuck at client machine-
        Location C:\ProgramData\McAfee\Agent\AgentEvents
        >>>>>>No Events are stucked at Client machine


   5.  Ensure that Eventparser service is running.
        >>>>>> Eventparser service is running fine at server side

Re: DLP Incidents not reflecting in incident manager

Jump to solution

Hi there, 

Sorry for replying so late, Last time I forgot to tell you one important thing, The thing is that last time I was testing the DATA PROTECTION rule that  I created earlier  with the same event. For example I was trying to send the same test-file which  was having the sensitive content  repeatedly. Rule was triggering properly at client side and incidents were generated in incident manager. After repeating it multiple times , Rule was still triggering but incidents stopped generating at incident manager.

So my question is that if there is a limit to number of incidents generated for the same event?

McAfee Employee DLP_RS
McAfee Employee
Report Inappropriate Content
Message 5 of 6

Re: DLP Incidents not reflecting in incident manager

Jump to solution

We should be seeing the incident each time it has been triggered. Please check for the following.

1. Are you able to trigger the rule now?

2. Once again verify the places(including Debug and rest of the folders on ePO and client) if the event is there? Also are you seeing reporting on ePO Dashboard for rest of the point products like MA|VSE|ENS?

3. What about the other rules? Are they triggering? Also check Database size?

I would suggest to log a service request for detailed troubleshooting by McAfee Technical Support. 

May be case of corrupt DLP extension and need to either upgrade to a higher one Or remove and reinstall it? 

Vaclav
Level 7
Report Inappropriate Content
Message 6 of 6

Re: DLP Incidents not reflecting in incident manager

Jump to solution

Hello,

we have probably a same issue, may I ask you what resolve the issue? Reinstall od DLP, or new version? Another question is how did you find out which machines were not working properly, we have hundreds of machines. So do you have any recomendations how to find which PC is incident free and which is faulty?

 

Thanks Václav

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community