Could someone please advise where can I find the DLP device control Incident logs.
If they are in DB, what is the SQL statement to fetch them.
DLP incidents will be logged under DLP Incident manager (Menu->data protection->DLP incident manager). You can see the events here.
There are many default DLP queries related to dlp incident. You can use them or can create new query from available 'Queries and reports'.
All types of DLP incidents are available for review under DLP Incident Manager. All you need is to refine the default settings for specific types of incidents. For example--
A list of available options appears. The list contains up to 250 of the most frequently occurring options.
If I understand correctly, it is an issue in blocking an external HDD. I have few suggestions.
1. Make sure that you are using DLP 11Patch 1 latest update.
2. Also review the KB-
In EPO, you should be able to see the incidents in the Incident Manager. Go to Menu, under Data Protection column, select DLP Incident Manager. There you should see a list and a graphical representation of all incidents, including Device Control incidents.