Showing results for 
Search instead for 
Did you mean: 

Duplicate DLP incidents while exporting using Query


Can someone sort out my issue with respect to Duplicate DLP incidents. When i checked DLP incident count of Email protection in DLP incident manager, it shows around 400 for past 24 hours. But when i exporting the DLP incident dump for email protection for past 24 hours, it gives around 30000 incidents.

After checking the incident dump, i got to know that Incident ID's are duplicate but evidence file different. I know its little confusing right, checked one incident ID in which user has sent around 20 attachment beacuse of this i'm getting huge number of duplicate incidents for one incident.


i would be more helpful if someone will solve my issue.

More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support
  • The McAfee ePO Support Center Plug-in is now available in the Software Manager. Follow the instructions in the Product Guide for more.