Hello all,
I've been facing an issue lately that you guys might be able to help.
I created a policy based on a IDM Indexed profile with 50 documents (mainly pdf with text/images).
With two-tier ON in agent config, the DLP is able to detect all data transfered by email/usb/print protocols. If I switch the two tier to OFF, all emails are still being captured on Network & Endpoint but only 3 out of 50 documents are captured/identifyed on usb/print. These 3 files which are always identified "matched exactly" while most of the other are "100% match" type.
Obviouslty, the test was done using the same files indexed.
My questions/doubts are:
1) whats the difference from "matched exactly" to "matched 100%" taking in consideration that all files were indexed correctly?
2) why only 3 out of 50 documents are identidified on usb/print protocols with two-tier OFF if they are all indexed?
3) why with two-tier ON I am not able to have any block (just a normal log on console) even on those incidents which are blocked with two-tier OFF? Does the two tier ON send always the documents to endpoint even if the agent can match it exactly?
4) why there are incidents which "matched exactly" on Network and are not captured on Endpoint (even as duplicate)? - So we lose the possiblity to use block/user cancel/notify automated response rules.
.
I am trying to avoid the two-tier ON feature due to it's high traffic/bandwidth demand (specially in a corporation with over 40K agents)
Technical details:
IDM policy created with 10% Minimum Document Exposure and Index archiving on Enforce Server local path
Enforce Svr and Endpoint Svr using 12.5.1 version with Network Monitor and Endpoint Prevent
Agent version: 12.5.0.20035
We do not own Network Prevent license
Different scenarios tested but with same issues:
- no use of response rules at all
- activate just endpoint channel
- split policy in two, one with Endpoint channel, other with Network
- different % of minimum document exposure
- added different profiles using upload document (zip) and local path on enforce (zip and pdf filetypes) - indexing runned smoothly
.
.
Thanks in advance,
Morgado