cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Jmac24
Level 12
Report Inappropriate Content
Message 1 of 3

Evidence file information

If we have evidence files on a file server and the related event in the DLP console in ePO has been purged, is there any way to retrieve any information on the leftover files. Basically the question asked of me is whether or not we can attribute a file to a specific user, machine or incident ID once the DLP event we alert on ages out and is purged. Thanks.

2 Replies
Corey-DLP
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Evidence file information

Hello and thank you for posting here!

Have all of the associated incidents also been purged out of the Incidents History table? If all associated incidents have been purged out of both incident tables, then unfortunately all identifiable information belonging to those incidents have also been deleted. There is a process in which the evidence file can be manually decrypted. This may provide you some insight. If you are interesting in this process, please contact McAfee Support to obtain the steps.

SWISS
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 3

Re: Evidence file information

Good question and i know where that comes from.

Are you on SQL Express or the full version?

It's always a problem and it always grows. I did see your post about the SIEM events 1092 and such cases can realy fill the SQL fast over night. You need to solve them with exlcusion ENS side.

We had to install the full version instead of SQL Standard on customers where we have DLP and TIE active in the EPO.

We also truncate that stuff backwards but did not export it before. We still have DUMPS and Veeam Backups of the Server for the worst case.

Related to DLP we Currently trunctae following table:

DELETE FROM DLP_EventInfo WHERE (InsertionTime < GETDATE() - 90)

 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community