Hey all,
I am new to DLP so this is probably a simple fix. When I go into DLP incidents and I click on the incident that I want to review, it shows the Evidence tab. For example, it may show a .xlsx file in Evidence. When I click on that file and try to open it, I get "access to evidence file denied".
Is this because I am logged into EPO mgmt console as a local user and this is a network file? Or what account is used, and which folder needs permissions adjusted?
It's not due to local or network accounts. Has the permissions on the DLP policy changed? Have you moved the DLP folder recently?
I have a same problem. ShareFolder has full permission with everyone, and the user can connect to sharefolder without authentication. But It still doesn't have any evidence.
I think this issue makes Registered document cannot work correctly.
Folow below link, I tested psexec but the access denied to foldershare.
How can we solve it?
Kindly check if your evidence share folder permissions is configured as per the steps in the KB below?
https://kb.mcafee.com/corporate/index?page=content&id=KB83365
Thank you
I checked the KB. All clients can connect to sharefolder, but it still cannot deploy RegDB to DLP users
C:\ProgramData\McAfee\DLP\Agent\IncrementalData\
I set permission for everyone - full control.
Do I miss something?
Verify that the user that the ePO Application Service (Tomcat.exe) is running as has permissions to the evidence share. Generally tomcat runs as system which would be the ePO server computer object but can be changed so verify the user then verify the permissions to the share.
Also refer KB: https://kc.mcafee.com/corporate/index?page=content&id=KB81399
check the DLP agent connectivity status within DLP endpoint console, it must be online (connected to corporate network) in order to replicate the evidence files. The DLP agent queries the ePO server every 30 seconds to decide its connectivity. FQDN of the ePO server should resolve successfully.
Dear team,
I find this issue on Window Server 2012 R2, the service network discovery is stuck.
You can apply to share all, but after the moment it will automatically disable again.
I followed this guide: https://www.youtube.com/watch?v=yQeBP2YyG9E
After that, check the share folder need to same on DLP settings and evidence storage (DLP policy - window configuration)
Thank you.
Today things are working randomly. I was able to download the files. Here is how I am setup if it helps anyone:
is is possible that you're purging older evidence files, but keeping the events?
I am new to DLP so where would that setting be? In the policy?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA