Short match string is no longer an available property in the DLP Incident Manager
a hotfix was applied to ePO 5.9.1 Build 251 on 6/14 (1229850 I think), our analysts (I am one of them) can no longer use Short match count as a filter property, although it is available as a View column. I feel as though something must be off our configuration -- whatever drives user permissions was modified during the hotfix install? My access is very limited and I do not have direct interaction with the group that owns the ePO system. Just trying to find some guidance that I can pass along. Filters with with "Short match string contains ..." are quite useful in our struggle with overwhelming false positives. Thanks in advance for any insight!
From the 11.0.300 release notes:
Disable reporting of short match string A setting on the Evidence Copy Service page of the client configuration gives you the option to not report the short match string in the incident details. The setting works in real time: if you change the setting, it only affects incidents reported by McAfee DLP Endpoint client from that point forward.
Encrypt short match string Short match strings are now encrypted at the event parser before being stored in the database. The Incident Details page automatically decrypts them for display in the Evidence → Short Match String field.
The benefit of encrypting the short match string at the event parser is that it also encrypts new incident information reported by older versions of McAfee DLP Endpoint, McAfee DLP Prevent, and McAfee DLP Monitor.