cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

Hi,

 

McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server, if the user in roaming.

 

Regards,

Kranthi

5 Replies
LKS
Employee
Employee
Report Inappropriate Content
Message 2 of 6

Re: McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

Hi kranthi.k,

It will reach to DB through the Remote Agent Handler. 

Was my reply helpful?

If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query!

Re: McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

Hi,

I have tested in one of our client, the incidents are able reach to EPO server through Agent handler but unable to download the incidents to view in incident list. 

Which is throughing error " the evidence is not available"

 

onedayoneapple
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 6

Re: McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

need to to add your epo server computer account to the DLP evidence share permissions with full access.

onedayoneapple
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 5 of 6

Re: McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

anohter possible reason is that evidence didnt got uploaded to the evidence share - can follow KB81399 for further troubleshooting.

jsubbura
Employee
Employee
Report Inappropriate Content
Message 6 of 6

Re: McAfee Endpoint DLP Incidents can reach to EPO server through Agent Handler Server

Hi @kranthi.k ,

Thank you for writing in here.

The error which you have mentioned is "evidence file not available" , this could be because the DLP Endpoint Console is showing as Not connected to Corporate Network and the DLP Incident Information in the DLP Incident Manager will show the connectivity state as Offline. 

not connected.PNG

 

When the DLP Endpoint console shows "Not Connected to Corporate Network", and when DLP generates Incidents , these Incidents can be parsed to your EPO via the DMZ Agent handler, however if DLP Endpoint console shows not connected to corporate network, the Evidence files stays with the client machine itself. 

These evidence files will be uploaded to the evidence share folder only when the the DLP Endpoint console shows "Connected to Corporate Network", to see when it can connect to corporate network and when it cannot, you would need to check the "Corporate Connectivity" settings under Windows Client Configuration policy assigned to this client machine from EPO.

For more possible scenarios, kindly have a view on the below kb,

https://kc.mcafee.com/corporate/index?page=content&id=KB81399&locale=en_US

 

Thank you.

Regards,
Jithendran S
Trellix Employee
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community