Troubleshooting evidence copy failures

Prev Next

Evidence copy can fail because of incorrect configurations, lack of storage space, or loss of network connectivity.

  • INCORRECT_EVIDENCE_SHARE]: The evidence share is incorrectly specified in the Shared Storage of Trellix DLP General Settings. If the share location (UNC) is misconfigured, the agent can't upload evidence files.

  • OUT_DISK_SPACE: The evidence share on the ePO - On-prem server has run out of disk space.

  • NETWORK_CONNECT: Due to loss of network connectivity between the appliance and the share or between ePO and the share.

Cause 1: Incorrectly specified evidence share

Solution: Verify the evidence share configuration

To verify the evidence share configuration in Policy Catalog:

  1. Log on to ePO - On-prem

  2. Select Policy CatalogData Loss Prevention <version>Server ConfigurationMy Default Server Configuration.

  3. Click Shared Storage and Evidence and verify the configuration.

To verify the evidence share configuration in DLP Settings:

  1. Log on to ePO - On-prem.

  2. Select Data ProtectionDLP Settings.

  3. On the General Settings page, in the Shared Storage section, verify the Shared Storage Location UNC or URL path provided.

To verify the evidence path against the share on the ePO - On-prem server, view the properties of the directory and click the Sharing tab. The UNC path for the evidence share is the correct display for Network Path.

Cause 2: Evidence share has run out of disk space

Solution: Free up the disk space on the drive where the evidence share was created.

Cause 3: Loss of network connectivity

Solution: Make sure that the share is reachable from ePO - On-prem and the appliance.

To verify if the share is reachable from ePO - On-prem:

  1. Select Data ProtectionDLP SettingsGeneral.

  2. In the Shared Storage section, add the correct Shared Storage Location path.

  3. Click Test Credential.

To test the connectivity from the appliance:

  1. Log on to the appliance ssh <appliance>.

  2. Run scm mash

  3. Go to MER and Diagnostic tests.

  4. Click Evidence share tests.

  5. Select the required test to see if connection is successful.