Data Loss Prevention

 View Only
  • 1.  No New Incidents appear in The Console

    Posted Aug 12, 2020 05:08 AM
    Hello,
    I have an issue that i can't see the Incidents of the Network Prevent for mail in the Console there were many incidents came before and i can see it but it is old incidents and when i use the Policy the new incidents not come and when we restart the enforce server the incidents come, the issue recurs and we can not restart the enforce server every time so any one has an advice with the solution of this problem.
    Thanks


  • 2.  RE: No New Incidents appear in The Console

    Broadcom Employee
    Posted Aug 12, 2020 09:18 AM
    Hello Moustafa,

    I would review the logs files for DLP up to the time is stops working and see if you can find any errors.  Here is a link to all the logs files and what they go with.


    I hope that helps.

    Paul 

    .





  • 3.  RE: No New Incidents appear in The Console

    Posted Aug 24, 2020 05:50 AM
    hello paul,
     
    the logs that i have doesn't contains any thing useful or errors
    unfortunately i still not found a solution for this problem is this problem appeared to you before ?


  • 4.  RE: No New Incidents appear in The Console

    Broadcom Employee
    Posted Aug 24, 2020 09:52 AM
    Turn on detection trace logging under system > server > logs for the detection server under the configuration tab.  Then reproduce and get the logs.  Search through the detection_operational_trace_0.log for the policy and see what the policy does.  Here is a link to the help guide on it.


    This helps alot to confirm if an incident is even being created.

    Thanks 
          
    Paul Evans


    .