Does anyone know if it is possible to configure ePO (DLP) or configure the ESM SQL pull to to grab portable media serial numbers? I have confirmed our ESM is receiving notifications from the ePO 5.10 > DLP device but the serial numbers are not present within the event data. I assume this can be done since I can see the media serial numbers within DLP Incident Manager. Any help would be greatly appreciated.
Please open a service request so that we can submit this to the McAfee SIEM Rules Engineering team as a defect.
If we are not pulling the serial numbers from the ePO Integrated DLP device, we may need to modify the query that we are using to pull the data from the ePO DB to include the portable media serial numbers from the DLP Incident Manager.
If the portable media serial numbers are present in the 'Packet' tab of the events on the ESM but not in the other tabs, you may need to fix the issue by creating a custom parser.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.