Data Loss Prevention

 View Only
  • 1.  getting alert into Enforce Server

    Posted Dec 15, 2014 08:55 PM

    Hi Team,

    today i got new error code:2316

    error summary: Over 1000000 incidents currently contained in the database .

    Error details: Persisting over 1000000 incidents can decrease database performance     

     

    kindly help me to understand about this alert and how should i resolve this.

     

    thanks

    Satya



  • 2.  RE: getting alert into Enforce Server

    Trusted Advisor
    Posted Dec 16, 2014 02:56 AM

    Hi Satya,

     For sure keeping over 1million incident in DB could decrease DLP performance.

    Best way to solve this is to delete some incidents in your database, for example by removing false positive incident, or older ones (or any other criteria acceptable for your company).

    If it si only the alert which bother you, you can increase this threshold in enforce configuration file Manager.properties (but i did not think it is good things to do).

    On other point that you have to think about is how many times it takes to reach this number of incident. If it takes less than a year, you should think about tuning your DLP policies.

     

     regards



  • 3.  RE: getting alert into Enforce Server

    Posted Dec 16, 2014 08:33 PM

    Hi Stephane, thanks for your responce. We can directly delete the incident from DLP console to make free space in DB?, Or any other way, kindly give me steps if have



  • 4.  RE: getting alert into Enforce Server

    Posted Dec 19, 2014 01:17 AM

    Even I have faced this error. The best way is to take backup of entire database(Cold Backup) and store it in a secured location and clean up DLP incidents. This error usually occurs when you are pulling out reports.  Cleaning up DLP incidents increases the performance of DLP .



  • 5.  RE: getting alert into Enforce Server

    Posted Dec 19, 2014 03:27 AM

    Yes, delete the incidents in Enforce will "delete flag" them and during the nightly cleanup remove them. Deleting 1'000'000 incidents however may take a while ;-) Be patient and I suggest you do the delete job Fridays.