Data Loss Prevention

 View Only
  • 1.  Symantec DLP detect multiple header count for Printer/Fax

    Posted Sep 24, 2018 10:37 AM
      |   view attached

    Hi All,

    My DLP endpoint agent is detecting multiple header count for Printer/Fax as per my screenshot, please advicse?

     



  • 2.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Trusted Advisor
    Posted Sep 25, 2018 02:42 PM

    What version of the Endpoint agent are you using? - there might be a hotfix for the agent version you ae using.

    Also what application is seeing this?

    It could be how the application is spooling the pinter job.

    Is this happening on all prints?

    Good Luck,

    PLEASE MARKED SOLVED WHEN POSSIBLE

    Ronak



  • 3.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Sep 26, 2018 05:58 AM

    We're using DLP Endpoint Agent 14.6, yes all printers.



  • 4.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Oct 22, 2018 12:14 AM

    Anybody with similar issue, this happened especially on Microsoft Word.



  • 5.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Nov 08, 2018 09:54 AM

    We see this on some printer/fax incidents.  We are on v15.0 using 14.6 agents.  We have very few policies actually monitoring print so we haven't put any effort into troubleshooting.



  • 6.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Nov 15, 2018 09:41 PM

    We set threshold for print policies, where it will only trigger incident on certain treshold, but due to this issue, its causing multiple false positive.



  • 7.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Nov 16, 2018 08:59 AM

    Hi DLP team, how many roles do you have on this policy ?



  • 8.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Dec 19, 2018 02:33 PM

    DLP team, the solution is to create the policy based on protocol exceptions. This will eliminate a match for the protocol completely.

    So in the policy create the detection rule for detecting whatever content you are interested in protecting.

    Then create an exception rule for protocols and select all the protocols EXCEPT print/fax.  This will result in policy being applied only when printing.



  • 9.  RE: Symantec DLP detect multiple header count for Printer/Fax

    Posted Dec 26, 2018 11:23 PM

    Hi Solution Provided by DLP Freak is best at the moment. We also faced similar issue with version 14.6 and 15.1 but was informed by Symantec that this is a known issue and there is a etrack number (I cannot recall it) pendig for resulation. 

     

    For threshholed you can use response rules based on Monitoring Protolol and select Printer\Fax.

     

    Regards