Data Loss Prevention

 View Only
Expand all | Collapse all

DLP network discover not working

deepak kasurde

deepak kasurdeSep 28, 2016 03:39 AM

deepak kasurde

deepak kasurdeSep 28, 2016 05:57 AM

deepak kasurde

deepak kasurdeSep 28, 2016 08:04 AM

deepak kasurde

deepak kasurdeSep 29, 2016 06:54 AM

  • 1.  DLP network discover not working

    Posted Sep 27, 2016 01:53 PM

    I have configured network discover with some policy but it is not working  and traffic is also not showing in console.

    both file server and discover on vm



  • 2.  RE: DLP network discover not working

    Posted Sep 27, 2016 01:56 PM

    I need to do any propertise setting for that 

    server network discover traffice is not showing like endpoint discover



  • 3.  RE: DLP network discover not working

    Posted Sep 28, 2016 01:12 AM

    Capture.PNG

    Not able to see any traffice in this policy is working fine for remoable media

    we need to define only quranatine reponse rule compulsory



  • 4.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 28, 2016 02:14 AM

    hello

     for network discover you have to define some complementary task :

    - scanner

    - scanner target

    - schedule period of run (or start one time scan)

     Network discover wont analyze storage content once installed as other detection servers.

     Regards



  • 5.  RE: DLP network discover not working

    Posted Sep 28, 2016 02:41 AM

    Hi Stephane,

     

    I Have created Content Root Enumeration successfully

    Add into scan target

    Define DCM Policy simply key word matching policy

    Assign to network discover policy group

    Define quarantine response rule

    Run the scan target manually 

     

    Capture1.PNG



  • 6.  RE: DLP network discover not working

    Posted Sep 28, 2016 02:54 AM

     find attached logs for more information.

    we are not getting  below mentioned logs 

    ScanDetail-target-0.log

    Attachment(s)



  • 7.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 28, 2016 03:34 AM

    hello

     what output do you have in "Scan History" page ?

    You should have amount of data analyzed / nb incident raised / nb errors and it must shows that scan is running?

     

     regards



  • 8.  RE: DLP network discover not working

    Posted Sep 28, 2016 03:39 AM

    Scan is running only or scanning



  • 9.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 28, 2016 05:51 AM

    did you see any increase in amount of data analyzed by DLP ? and total amount of data to be analyzed by scanner ?



  • 10.  RE: DLP network discover not working

    Posted Sep 28, 2016 05:57 AM

    After any scanning  it showin only scanning.

    Capture2.PNG



  • 11.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 28, 2016 07:25 AM

    it looks like there is no directory to scan on your target (no errors / no data analyzed).

    did you define some directory to scan in target def ? did you check that they are accessible from your discover server (in this case usually there is an error message but...) ?



  • 12.  RE: DLP network discover not working

    Posted Sep 28, 2016 07:50 AM

    if you have any best practice to follow send me

    share drive is accessible from 



  • 13.  RE: DLP network discover not working

    Posted Sep 28, 2016 08:04 AM

    because of alerts we are not getting share driveen.PNg

     



  • 14.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 29, 2016 02:40 AM

    hello deepak,

    so looks like this is your main issue, content root enumeration does not work.

     coudl you share with us message content of these alert ?

     Regards



  • 15.  RE: DLP network discover not working

    Posted Sep 29, 2016 06:53 AM

    Find alerts logs

    but I am seraching only one ip address at time.Capture._3PNG.PNG



  • 16.  RE: DLP network discover not working

    Posted Sep 29, 2016 06:54 AM

    for that ip i get proper share drive



  • 17.  RE: DLP network discover not working

    Trusted Advisor
    Posted Sep 30, 2016 10:35 AM

    hello

     1/ you could try to paste and copy shared drive names from content root enumeration into target scan def...this will allow us to know if issue is due to content root enumeration or scanners

    2/ Check into this shared drive if there is any file to scan (not excluded by your target scan configuration (if you set any filters in it)). Do this operation from your discover servers and with account defined in your discover target.

     

    you wrote there is no ScanDetail-target-0.log available...did you check if you have this file available on discover server ?

     Regards



  • 18.  RE: DLP network discover not working
    Best Answer

    Posted Oct 12, 2016 02:59 AM

    Thanks for reply guys

    Issue is resolved it was releated ot AD.

    I have created new test AD and sync with that