Troubleshooting tips

Prev Next

Use this information to identify and troubleshoot issues with installing, registering, using, and maintaining Trellix DLP.

Use the appliance console for general maintenance tasks such as changing network settings and performing software updates. Troubleshooting options, sanity checks, and error messages are available to help you identify and resolve problems with appliances.

The appliance failed to register with ePO - On-prem

Verify that the network connection is working, and any static routes that you created are correct. Ping the default gateway and ePO - On-prem from the appliance console to test your network connection.

Important

If the registration continues to fail, call Technical Support. Do not try to register again.

Connection between ePO - On-prem and the appliance is lost

You can verify the connection status for all your physical and virtual appliances using the Appliance Management feature in ePO - On-prem.

To restore a failed connection, open the System Tree and select the appliance that has lost the connection. Then select ActionAgentWake Up Agents and click OK.

Registration failures

Registration events are available from the DLP Operations log in ePO - On-prem.

Event ID

UI event text

Description

19402

DLP Network Prevent Registered

The appliance successfully registered with ePO - On-prem.

Event ID

UI event text

Description

19403

DLP Network Monitor Registered

The appliance successfully registered with ePO - On-prem.

No events are sent if the appliance is not registered. You can get more information from /var/log/messages.

Email delivery issues

If an email is not delivered, verify whether it is blocked by a Trellix DLP Network Prevent. Go to the DLP Incident Manager in ePO - On-prem to verify if there is any corresponding incident for the message.

If email notification is configured in ePO - On-prem as a Reaction, the sender is notified.

Verify if the Smart Host can receive email, if:

  • Trellix DLP Network Prevent appliance could not connect to the Smart Host to send the message.

  • The connection to Smart Host was dropped during a conversation.

Email rejection issues

If a Smart Host is not configured, the Trellix DLP Network Prevent appliance can't accept email messages because it has nowhere to send them to.

Web Gateway and Trellix DLP Network Prevent ICAP issues

Verify the Trellix DLP Web Settings category settings in DLP Appliance Management in Policy Catalog. Trellix DLP Network Prevent processes ICAP and ICAPs traffic based on selected services from secure ICAP, unencrypted.

If neither is selected, the ICAP server on the Trellix DLP Network Prevent appliance does not accept any connection.

If only secure ICAP is enabled, make sure that the ICAP client is ICAPs capable.

You can select the modes where Trellix DLP Network Prevent appliance can operate for the ICAP traffic from REQMOD and RESPMOD. If any mode is deselected, that traffic is ignored by the Trellix DLP Network Prevent appliance and is not processed. REQMOD and RESPMOD can't be disabled at the same time.

LDAP and Trellix - LC issues

If there are communication issues between the appliance and the Active Directory while querying user information:

  • Verify the Active Directory credentials configured on ePO - On-prem.

  • If SSL is selected, verify that Active Directory accepts secure connections.

If you configured Active Directory to use Global Catalog ports, check that at least one of these attributes is replicated to the Global Catalog server from the domains in the forest:

  • Proxy addresses

  • Mail

If an appliance needs to use NTLM authentication for ICAP traffic, these LDAP attributes must also be replicated:

  • configurationNamingContext

  • netbiosname

  • msDS-PrincipalName

For Trellix - LC, verify the Trellix - LC certificate in the appliance.

Extension installation failures

  • Dependency issues — There might be a dependency issue if the following extensions are missing:

    • Common UI package

    • Appliance Management Extension

    • Data Loss Prevention Management Extension

  • Upgrade issues — the following error occurs if you install the same version or earlier version of the extension: Can't upgrade the extension dlp-prevent-server-app to <version x.x.x.x > because <version x.x.x.x> is already installed.

Policy push failures

Policy push events are also available from the DLP Operations log in ePO - On-prem.

If policy push fails, details can be obtained from the appliance at /wk/mca/ ame_policy_DLPPS___1000_error.log

System health

The Appliance Management dashboard in ePO - On-prem provides information to manage your appliances, view system health status, and get detailed information about alerts.

System health show status of:

  • Evidence Queue

  • Email and web requests (Trellix DLP Network Prevent)

  • Packet analysis (Trellix DLP Network Monitor)

  • CPU usage

  • Memory

  • Disk

  • Network

Displays errors or warnings that relate to:

  • System health

  • Evidence queue size

  • Policy enforcement

  • Communication between ePO - On-prem and appliances.

Viewing client events

Issues with user, LDAP, or certificate installation are listed in the Client Events page.

  1. In ePO - On-prem, go to the System Tree.

  2. Select the checkbox next to the appliance.

  3. Select Actions, then go to AgentShow Client Events.

Incidents are not showing in the DLP Incident Manager

  1. Use the Remote Desktop Protocol (RDP) to access ePO - On-prem.

  2. Go to Services.

  3. Confirm that the ePO - On-prem Event Parser is running. If it has stopped or paused, restart it to resolve the issue.

Setting up remote log servers

Logging information is sent to the local syslog, and one or more remote logging servers if you have them enabled. Syslog entries contain information about the device itself (the vendor, product name, and version), the severity of the event, and the date the event occurred. Use Logging settings in the General category of the Policy CatalogCommon Appliance Management policy to set up remote logging servers.