Troubleshooting tips

Prev Next

Use this information to identify and troubleshoot issues with installing, registering, using, and maintaining Trellix DLP – SaaS.

The appliance failed to register with ePO - SaaS

The registration with ePO - SaaS can fail due to one or a combination of these reasons:

  • Invalid Short Registration Token

  • Invalid IP address of the web proxy server

  • Invalid port of the web proxy server

  • Invalid user name and password for the web proxy server

  • Proxy is unable to reach the destination web or cloud service

Verify that the SRT token and proxy configuration settings are correct.

Verify that the network connection is working, and any static routes that you created are correct. Ping the default gateway and ePO - SaaS from the appliance console to test your network connection.

Important

If the registration continues to fail, call Technical Support. Do not try the registration again.

Connection between ePO - SaaS and the appliance is lost

You can verify the connection status for all your physical and virtual appliances using the Appliance Management feature in ePO - SaaS.

To restore a failed connection to a registered appliance, open the System Tree and select the appliance that has lost the connection. Then select ActionAgentWake Up Agents and click OK.

Connection between and the appliance is lost

You can verify the connection status for all your physical and virtual appliances using the Appliance Management feature in .

To restore a failed connection, open the System Tree and select the appliance that has lost the connection. Then select ActionAgentWake Up Agents and click OK.

Email delivery issues

If an email is not delivered, verify whether it is blocked by Trellix DLP Network Prevent – SaaS. Go to the Protection Workspace in to verify if there is any corresponding incident for the message.

If email notification is configured in ePO - SaaS as a Reaction, the sender is notified.

Verify if the Smart Host can receive email, if:

  • could not connect to the Smart Host to send the message.

  • The connection to Smart Host was dropped during a conversation.

Email rejection issues

If a Smart Host is not configured, Trellix DLP Network Prevent – SaaS can't accept email messages because it has nowhere to send them to.

Web Gateway and Trellix DLP Network Prevent – SaaS ICAP issues

Verify the Trellix DLP Web Settings category settings in DLP Appliance Management in Policy Catalog. Trellix DLP Network Prevent – SaaS processes ICAP and ICAPs traffic based on selected services from secure ICAP, unencrypted.

If neither is selected, the ICAP server on does not accept any connection.

If only secure ICAP is enabled, make sure that the ICAP client is ICAPs capable.

You can select the modes where Trellix DLP Network Prevent – SaaS can operate for the ICAP traffic from REQMOD and RESPMOD. If any mode is deselected, that traffic is ignored by Trellix DLP Network Prevent – SaaS appliance and is not processed. REQMOD and RESPMOD can't be disabled at the same time.

LDAP and Trellix - LC issues

If there are communication issues between the appliance and the Active Directory while querying user information:

  • Verify the Active Directory credentials configured on ePO - SaaS.

  • If SSL is selected, verify that Active Directory accepts secure connections.

If you configured Active Directory to use Global Catalog ports, check that at least one of these attributes is replicated to the Global Catalog server from the domains in the forest:

  • Proxy addresses

  • Mail

If an appliance needs to use NTLM authentication for ICAP traffic, these LDAP attributes must also be replicated:

  • configurationNamingContext

  • netbiosname

  • msDS-PrincipalName

For Trellix - LC, verify the Trellix - LC certificate in the appliance.

System health

The Appliance Management dashboard in ePO - SaaS provides information to manage your appliances, view system health status, and get detailed information about alerts.

System health show status of:

  • Evidence Queue

  • Email and web requests ( Trellix DLP Network Prevent – SaaS)

  • Packet analysis ( Trellix DLP Network Monitor – SaaS)

  • CPU usage

  • Memory

  • Disk

  • Network

Displays errors or warnings that relate to:

  • System health

  • Evidence queue size

  • Policy enforcement

  • Communication between ePO - SaaS and appliances.

Viewing client events

Issues with user, LDAP, or certificate installation are listed in the Client Events page.

  1. In ePO - SaaS, go to the System Tree.

  2. Select the checkbox next to the appliance.

  3. Select Actions, then go to AgentShow Client Events.

Setting up remote log servers

Logging information is sent to the local syslog, and one or more remote logging servers if you have them enabled. Syslog entries contain information about the device itself (the vendor, product name, and version), the severity of the event, and the date the event occurred. Use Logging settings in the General category of the Policy CatalogCommon Appliance Management policy to set up remote logging servers.