cancel
Showing results for 
Search instead for 
Did you mean: 

Duplicate DLP incidents while exporting using Query

Hi,

Can someone sort out my issue with respect to Duplicate DLP incidents. When i checked DLP incident count of Email protection in DLP incident manager, it shows around 400 for past 24 hours. But when i exporting the DLP incident dump for email protection for past 24 hours, it gives around 30000 incidents.

After checking the incident dump, i got to know that Incident ID's are duplicate but evidence file different. I know its little confusing right, checked one incident ID in which user has sent around 20 attachment beacuse of this i'm getting huge number of duplicate incidents for one incident.

 

i would be more helpful if someone will solve my issue.

ePO Support Center Plug-in
Check out the new ePO Support Center. Simply access the ePO Software Manager and follow the instructions in the Product Guide for the most commonly used utilities, top known issues announcements, search the knowledgebase for product documentation, and server status and statistics – all from within ePO.