Video Screencast Help

No new incident

Created: 23 Jan 2013 | 9 comments
Aidaho's picture

Hi! I installed a new DLP, but after setting no new incidents. There Incident Queue, but not new. For the test created two new Response Rules: One blocks and creates incident: "Endpoint Prevent: Block" and "All: Set Status: New", just creating another incident. Blocking works, but there is no incident. Tell me what's the problem?

 

It looks like this:

        Messages
(Last 10 sec)
Messages
(Today)
Incidents
(Today)
Incident Queue Message Wait Time
Running Enforce Server 11.6.0.19032 N/A N/A N/A N/A 0 N/A  
Running test_monitor 11.6.0.19032 Network Monitor, Network Prevent for E-mail, Network & Mobile Prevent for Web, Endpoint, Network Discover 8 38 536 0 925 0:00:00

 

Comments 9 CommentsJump to latest comment

Artem's picture

Hello,

Try to restart Vontu Monitor Controller service on the Enforce server.

Aidaho's picture

Thank you very much helped. It is not clear problem.

pete_4u2002's picture

is the end user getting pop up for the incident?

yang_zhang's picture

It seems all the incidents are queued on your detection server (test_monitor). Could you check the connection between your Enforce server and test_monitor? I wonder there is some proble with your Enforce server to receive the incidents from test_monitor.

If a forum post solves your problem, please flag it as a solution. If you like an article, blog post or download vote it up.
pete_4u2002's picture

is the endpoint communicating to detection server.

is detection server status ok?

Artem's picture

Hello collegues,
I have met on several installations in which service Monitor Controller freezes. A simple restart of the Vontu Monitor Controller service is helps.
Once I tried to get to the bottom. I discovered that the file \Vontu\Protect\config\EnvironmentCheckUtility.properties contains the following lines:
ecu.incidentpersister = VontuIncidentPersister.ex
ecu.monitorcontroller = VontuMonitorController.ex

Judging by the title config file - there are executables process files, for which we need to control. Following this logic, I changed lines to the following:
ecu.incidentpersister = VontuIncidentPersister.exe
ecu.monitorcontroller = VontuMonitorController.exe
and I restarted the Enforce services. I do not remember exactly what happened in this case: either not result at all, or even worse.
At the time, I wasn't able to connect with Symantec support. And I came out of the situation by creating a bat-file restarts VontuMonitorController service and put it to run in a schedule (every 3 hours) in the Windows Scheduler.
Since then, I stopped to dig the matter and, if I meet the same problem, go on to the same algorithm.

---
Best regards, Artem.

kishorilal1986's picture

Hi Adaho,

Please restart the vontu services is pririty manner as mentioned in DLP Admin guide.

Incient persiter service might not writing the incident to database also check the AD integration and DB communication with enforce servers.

jgt10's picture

If the incidents aren't showing up there are several things to check.

 

On the detection server check the incidents folder to see if the incidents are queuing up there. If they are, open a support case to determine the cause.

In the GUI check the system -> overview -> enforce and make sure the monitor controller is running. If it isn't, start it.

If the monitor controller was runing, restart it.

If that doesn't fix the problem, restart all the servers.

If that doesn't fix the problem, open a support case.

JGT

 

--
John G. Thompson
JOAT(MON)