Trellix DLP Network system health cards

Prev Next

System health information helps you manage all virtual and physical Trellix appliances on your network. Apart from the Evidence Queue counter, the counters are not cumulative.

Trellix DLP Network Prevent health cards

The system health cards show the following information for each Trellix DLP Network Prevent system and cluster of systems.

Note

In a cluster environment, the tree view displays a cluster primary appliance and two or more cluster scanners.

The primary statistics (data received rate and total CPU utilization) are displayed beneath the appliance name. These statistics are the two items of information that are considered the most important for the appliance type. To the right of the primary statistics are the other health statistics of the appliance. These statistics vary, depending on the type of appliance to which they relate.

The status is displayed in green, amber, or red and the status appears as grayed-out if the parameter isn't applicable to the appliance. The status color depends on whether warning and critical threshold values have exceeded, or if there is an error. The status value (such as 0, 1, usage %, OK, or OFF) that is shown at the end of the graph, is most latest status. More information is provided in the Alerts and Details panes to analyze any error and troubleshoot the error accordingly.

Note

The line graphs show the health status for the last 24 hours. You can see the last refreshed time at the top of the System Health card. To see the latest status, refresh the browser. For optimal performance of the system, the interval between the data points is four minutes.

Pane

Information

System Health

  • Evidence Queue — The number of evidence files waiting to be copied to evidence storage. The queue size is real-time.

  • Emails — The total number of messages that are processed, including the delivered, temporarily or permanently rejected messages. The counters show data from the previous 60 seconds.

  • Web Requests — The total number of web requests that the Trellix DLP Network Prevent system processed in a minute, and the number it could not analyze. The counters show data from the previous 60 seconds.

  • CPU usage — The total CPU usage.

  • Memory — The memory swap rate.

  • Disk — The information about the disk partitions and their usage.

  • Network — The network interfaces on the system, showing information about received and transmitted data. The counters show data from the previous 60 seconds.

  • Capture — (Optional) The following statistics are shown when the DLP Capture feature is enabled on the system.

    • Estimated capacity (days) — The estimated number of days remaining before the capture storage reaches its capacity.

    • Oldest item (days) — The age of the oldest captured item.

    • Searches running — The number of searches currently in progress.

  • OCR Scan — These statistics are shown when the OCR feature is used on the system,.

    • Total — Total number of images that are scanned completely.

    • Queue Size — The number of images to be scanned that are held in a queue.

Process States — Helps identify the health status of processes or services that are running in the system. It shows whether a process is running properly, turned off, or not functioning.

To reduce the load on the system processes or services, you can configure the interval of health check queries sent to the system processes or services or disable the health check queries. For information about configuring the query interval, see KB96788.

  • Common Process States

    • mca — The status of the Trellix Common Appliance processes.

      MCA is the Common Appliance agent that is responsible for the exchange of information between Trellix DLP Network and ePO - On-prem. If MCA is unavailable, the communication between Trellix DLP Network and ePO - On-prem fails.

    • cma — The status of Common Management Agent (CMA), which is also referred to as Trellix Agent. If CMA is unavailable, the communication between the appliance and ePO - On-prem fails.

    • crond — The status of crond process. Crond is a background process that runs specified programs at scheduled time.

      If the crond process stops functioning or is turned off on the appliance, the execution of cron jobs is affected.

    • incrond — The status of incrond process. Incrond is a background process that monitors any change in the filesystem.

      If this process stops functioning or is turned off on the appliance, the execution of jobs is affected when there is a change in the filesystem.

    • tmgr — (Available only when DLP Capture is enabled on appliances.) The status of task manager service (tmgr).

      Tmgr is a service that receives the capture search requests, processes them, and returns the capture search completion status.

    • postgres — (Available only when DLP Capture is enabled on appliances.) The status of Postgres.

      Postgres is a database service that is used to store metadata processed by the tmgr service.

    • ntp — The status of network time protocol service. Used for clock synchronization.

    • named — The status of the named service. Named is the name of a service used for DNS (Dynamic Name Service) lookups that run in the background.

    • mlcdaemon — The status of Trellix Logon Collector process running in the background.

    • redis — The status of Redis. Redis is an in-memory database that contains data, which is used by scanning service to determine if the content is unscannable and returns SCANFAIL. It also stores user logon data processed by Trellix Logon Collector.

    • evthandler — The status of event handler.

    • snmpd — (Available only when snmpd is enabled on systems.) Shows the status of the snmpd service. snmpd is an SNMP agent that binds to a port and awaits requests from SNMP management software. Upon receiving a request, it processes the requests, collects the requested information and/or performs the requested operations, and then returns the information to the sender.

  • Stunnel State

    • stunnel — (Applicable to a cluster of systems.) The status of stunnel state. Stunnel converts non-secure TCP connections to secure connections.

  • Prevent Only Process States

    • smtp — The status of SMTP service that is running in the system.

    • icap — The status of ICAP service that is running in the system.

  • Other Process States

    • evidenceservice — The status of evidence service.

    • scanningservice — The status of scanning service.

    • evdmonitor — The status of evidence monitor.

Alerts

Displays errors or warnings that relate to:

  • System health statuses

  • Evidence queue size

  • Policy enforcement

  • Communication between ePO - On-prem and Trellix DLP Network .

  • Health status of the processes or services running in the system

More information about an alert is available on the Details pane.

Trellix DLP Network Monitor health cards

The system health cards show information for each Trellix DLP Network Monitor system and cluster of systems.

Note

In a cluster environment, the tree view displays a cluster packet acquisition device, a cluster primary appliance, and two or more cluster scanners.

The primary statistics (data received rate and total CPU utilization) are displayed beneath the appliance name. These statistics are the two items of information that are considered the most important for the appliance type. To the right of the primary statistics are the other health statistics for the appliance. These statistics vary, depending on the type of appliance to which they relate.

The status is displayed in green, amber, or red and the status appears as grayed-out if the parameter isn't applicable to the appliance. The status color depends on whether warning and critical threshold values have exceeded, or if there is an error. The status value (such as 0, 1, usage %, OK, or OFF) that is shown at the end of the graph, is most latest status. More information is provided in the Alerts and Details panes to analyze any error and troubleshoot the error accordingly.

Note

The line graphs show the health status for the last 24 hours. You can see the last refreshed time at the top of the System Health card. To see the latest status, refresh the browser. For optimal performance of the system, the interval between the data points is four minutes.

Pane

Information

System Health

  • Evidence Queue — The number of evidence files waiting to be copied to evidence storage. The queue size is real-time.

    This statistic does not apply to a packet acquisition device.

  • CPU usage — The total CPU usage.

  • Memory — The memory swap rate, and memory usage and swap usage details.

  • Disk — The information about the disk partitions and its usage.

  • Network — The network interfaces on the appliance, showing information about received and transmitted data through the capture1 port. The following capture1 port details are displayed for a standalone appliance and cluster packet acquisition device:

    • Packets per second — The number of packets processed by the Trellix DLP Network Monitor packet acquisition device every second.

    • Packet drops — The number of packets dropped at the network interface.

      Details about dropped packets can be obtained from your virtual application.

  • Monitor — Monitors the following information (these statistics apply to a standalone system and cluster packet acquisition device):

    • Active flows — The current number of conversations on your network tracked by the Trellix DLP Network Monitor packet acquisition device.

    • Flows filtered — The current number of conversations that are not scanned according to filter rules.

    • Payloads scanned — Displays the number of payloads analyzed by the Trellix DLP Network Monitor packet acquisition device, which had classifications applied, and matched against the appropriate rules. A payload is a single transaction on the network, such as a download from a website.

    • Payload scan failure — Displays the number of payloads that can't be analyzed if, for example, an email message is corrupt or the time to analyze the payload exceeds the analysis settings configured in Policy Catalog DLP Appliance ManagementGeneralAnalysis Settings.

    • Payloads oversize — Displays the number of payloads that exceed the limit configured in Policy Catalog DLP Appliance ManagementGeneralAnalysis Settings. Trellix DLP Network Monitor analyzes data up to the configured limit, even if the data is incomplete or has been truncated.

      Trellix DLP Network Monitor can't analyze partially extracted .zip files.

  • Capture — (Optional) The following statistics are shown when the DLP Capture feature is enabled on the appliance.

    • Estimated capacity (days) — The estimated number of days remaining before the capture storage reaches its capacity.

    • Oldest item (days) — The age of the oldest captured item.

    • Searches running — The number of searches currently in progress.

  • OCR Scan — These statistics are shown when the OCR feature is used on the appliance.

    • Total — Total number of images that are scanned completely.

    • Queue Size — The number of images to be scanned that are held in a queue.

Process States — Helps identify the health status of processes or services that are running in the appliance. It shows whether a process is running properly, turned off, or not functioning properly.

To reduce the load on the appliance processes or services, you can configure the interval of health check queries sent to the appliance processes or services or disable the health check queries. For information about configuring the query interval, see KB96788.

  • Common Process States

    • mca — The status of the Trellix Common Appliance processes.

    • MCA is the Common Appliance agent that is responsible for the exchange of information between the Trellix DLP appliance and Trellix ePO - On-prem. If MCA is unavailable, the communication between the appliance and Trellix ePO - On-prem fails.

    • cma — The status of Common Management Agent (CMA), which is also referred to as Trellix Agent. If CMA is unavailable, the communication between the appliance and ePO - On-prem fails.

    • crond — The status of crond process. Crond is a background process that runs specified programs at scheduled time.

      If the crond process stops functioning or is turned off on the appliance, the execution of cron jobs is affected.

    • incrond — The status of incrond process. Incrond is a background process that monitors any change in the filesystem.

      If this process stops functioning or is turned off on the appliance, the execution of jobs is affected when there is a change in the filesystem.

    • tmgr — (Available only when DLP Capture is enabled on appliances.) The status of task manager service (tmgr).

      Tmgr is a service that receives the capture search requests, processes them, and returns the capture search completion status.

    • postgres — (Available only when DLP Capture is enabled on systems.) The status of Postgres.

      Postgres is a database service that is used to store metadata processed by the tmgr service.

    • ntp — The status of network time protocol service. Used for clock synchronization.

    • named — The status of the named service. Named is the name of a service used for DNS (Dynamic Name Service) lookups that run in the background.

    • mlcdaemon — The status of Trellix Logon Collector process running in the background.

    • redis — The status of Redis. Redis is an in-memory database that contains data, which is used by scanning service to determine if the content is unscannable and returns SCANFAIL. It also stores user logon data processed by Trellix Logon Collector.

    • evthandler — The status of event handler.

    • snmpd — (Available only when snmpd is enabled on systems.) Shows the status of the snmpd service. snmpd is an SNMP agent that binds to a port and awaits requests from SNMP management software. Upon receiving a request, it processes the requests, collects the requested information and/or performs the requested operations, and then returns the information to the sender.

  • Stunnel State

    • stunnel — (Applicable to a cluster of systems.) The status of stunnel state. Stunnel converts non-secure TCP connections to secure connections.

  • Monitor Only Process States

    • dpi — The status of Deep Packet Inspection (DPI) service. DPI is a service used to inspect data packets in IP networks.

  • Other Process States

    • evidenceservice — The status of evidence service.

    • scanningservice — The status of scanning service.

    • evdmonitor — The status of evidence monitor.

Alerts

Displays errors or warnings that relate to:

  • System health statuses

  • Evidence queue size

  • Payload scan failures

  • Policy enforcement

  • Communication between ePO - On-prem and the system.

  • Health status of the processes or services running in the system

More information about an alert is available on the Details pane.