Hello Team,
We were testing Data Protection rules on our test machines until yesterday everything seems to be working fine. Now what is happening is rules are triggering as expected and events are also getting generated in the client DLP 11 console but the same events are not reflecting in incident manager earlier we were able to view the incidents in incident manager.
Thanks in advance
Solved! Go to Solution.
We should be seeing the incident each time it has been triggered. Please check for the following.
1. Are you able to trigger the rule now?
2. Once again verify the places(including Debug and rest of the folders on ePO and client) if the event is there? Also are you seeing reporting on ePO Dashboard for rest of the point products like MA|VSE|ENS?
3. What about the other rules? Are they triggering? Also check Database size?
I would suggest to log a service request for detailed troubleshooting by McAfee Technical Support.
May be case of corrupt DLP extension and need to either upgrade to a higher one Or remove and reinstall it?
Suggestions--
1. Please check if under Eventparser.log if there are any errors while processing the events. Location
C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Logs Or may vary if you have installed ePO in a different drive.
2. Are there any unprocessed events in ePO server- Also any other point product is impacted?
C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Events
3. Check the Database size if it is not Full.
4. Also verify if events are not stuck at client machine-
C:\ProgramData\McAfee\Agent\AgentEvents
5. Ensure that Eventparser service is running.
Please find the below observation as per your instruction.
>>>>> I dont think there is any unprocessed events, I might be wrong here but I dont see any events there
The only thing is see there is the two others folder namely 1)Debug 2)Unknown
2. Please check if under Eventparser.log if there are any errors while processing the events. Location
C:\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Logs Or may vary if you have installed ePO in a different drive.
>>>>>>I dont think there is an error with processing here Please find the below example
HOSTDLPEVENT Processed event successfully. Time elapsed: (in ms): 31
4. Also verify if events are not stuck at client machine-
Location C:\ProgramData\McAfee\Agent\AgentEvents
>>>>>>No Events are stucked at Client machine
5. Ensure that Eventparser service is running.
>>>>>> Eventparser service is running fine at server side
Hi there,
Sorry for replying so late, Last time I forgot to tell you one important thing, The thing is that last time I was testing the DATA PROTECTION rule that I created earlier with the same event. For example I was trying to send the same test-file which was having the sensitive content repeatedly. Rule was triggering properly at client side and incidents were generated in incident manager. After repeating it multiple times , Rule was still triggering but incidents stopped generating at incident manager.
So my question is that if there is a limit to number of incidents generated for the same event?
We should be seeing the incident each time it has been triggered. Please check for the following.
1. Are you able to trigger the rule now?
2. Once again verify the places(including Debug and rest of the folders on ePO and client) if the event is there? Also are you seeing reporting on ePO Dashboard for rest of the point products like MA|VSE|ENS?
3. What about the other rules? Are they triggering? Also check Database size?
I would suggest to log a service request for detailed troubleshooting by McAfee Technical Support.
May be case of corrupt DLP extension and need to either upgrade to a higher one Or remove and reinstall it?
Hello,
we have probably a same issue, may I ask you what resolve the issue? Reinstall od DLP, or new version? Another question is how did you find out which machines were not working properly, we have hundreds of machines. So do you have any recomendations how to find which PC is incident free and which is faulty?
Thanks Václav
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA