Use this information to identify and troubleshoot issues with installing, registering, using, and maintaining Trellix DLP.
Use the appliance console for general maintenance tasks such as changing network settings and performing software updates. Troubleshooting options, sanity checks, and error messages are available to help you identify and resolve problems with appliances.
The appliance failed to register with ePO - On-prem
Verify that the network connection is working, and any static routes that you created are correct. Ping the default gateway and ePO - On-prem from the appliance console to test your network connection.
Important
If the registration continues to fail, call Technical Support. Do not try to register again.
Connection between ePO - On-prem and the appliance is lost
You can verify the connection status for all your physical and virtual appliances using the Appliance Management feature in ePO - On-prem.
To restore a failed connection, open the System Tree and select the appliance that has lost the connection. Then select Action → Agent → Wake Up Agents and click OK.
Registration failures
Registration events are available from the DLP Operations log in ePO - On-prem.
Event ID | UI event text | Description |
19402 | DLP Network Prevent Registered | The appliance successfully registered with ePO - On-prem. |
Event ID | UI event text | Description |
19403 | DLP Network Monitor Registered | The appliance successfully registered with ePO - On-prem. |
No events are sent if the appliance is not registered. You can get more information from /var/log/messages.
Email delivery issues
If an email is not delivered, verify whether it is blocked by a Trellix DLP Network Prevent. Go to the DLP Incident Manager in ePO - On-prem to verify if there is any corresponding incident for the message.
If email notification is configured in ePO - On-prem as a Reaction, the sender is notified.
Verify if the Smart Host can receive email, if:
Trellix DLP Network Prevent appliance could not connect to the Smart Host to send the message.
The connection to Smart Host was dropped during a conversation.
Email rejection issues
If a Smart Host is not configured, the Trellix DLP Network Prevent appliance can't accept email messages because it has nowhere to send them to.
Web Gateway and Trellix DLP Network Prevent ICAP issues
Verify the Trellix DLP Web Settings category settings in DLP Appliance Management in Policy Catalog. Trellix DLP Network Prevent processes ICAP and ICAPs traffic based on selected services from secure ICAP, unencrypted.
If neither is selected, the ICAP server on the Trellix DLP Network Prevent appliance does not accept any connection.
If only secure ICAP is enabled, make sure that the ICAP client is ICAPs capable.
You can select the modes where Trellix DLP Network Prevent appliance can operate for the ICAP traffic from REQMOD and RESPMOD. If any mode is deselected, that traffic is ignored by the Trellix DLP Network Prevent appliance and is not processed. REQMOD and RESPMOD can't be disabled at the same time.
LDAP and Trellix - LC issues
If there are communication issues between the appliance and the Active Directory while querying user information:
Verify the Active Directory credentials configured on ePO - On-prem.
If SSL is selected, verify that Active Directory accepts secure connections.
If you configured Active Directory to use Global Catalog ports, check that at least one of these attributes is replicated to the Global Catalog server from the domains in the forest:
Proxy addresses
Mail
If an appliance needs to use NTLM authentication for ICAP traffic, these LDAP attributes must also be replicated:
configurationNamingContext
netbiosname
msDS-PrincipalName
For Trellix - LC, verify the Trellix - LC certificate in the appliance.
Extension installation failures
Dependency issues — There might be a dependency issue if the following extensions are missing:
Common UI package
Appliance Management Extension
Data Loss Prevention Management Extension
Upgrade issues — the following error occurs if you install the same version or earlier version of the extension: Can't upgrade the extension dlp-prevent-server-app to <version x.x.x.x > because <version x.x.x.x> is already installed.
Policy push failures
Policy push events are also available from the DLP Operations log in ePO - On-prem.
If policy push fails, details can be obtained from the appliance at /wk/mca/ ame_policy_DLPPS___1000_error.log
System health
The Appliance Management dashboard in ePO - On-prem provides information to manage your appliances, view system health status, and get detailed information about alerts.
System health show status of:
Evidence Queue
Email and web requests (Trellix DLP Network Prevent)
Packet analysis (Trellix DLP Network Monitor)
CPU usage
Memory
Disk
Network
Displays errors or warnings that relate to:
System health
Evidence queue size
Policy enforcement
Communication between ePO - On-prem and appliances.
Viewing client events
Issues with user, LDAP, or certificate installation are listed in the Client Events page.
In ePO - On-prem, go to the System Tree.
Select the checkbox next to the appliance.
Select Actions, then go to Agent → Show Client Events.
Incidents are not showing in the DLP Incident Manager
Use the Remote Desktop Protocol (RDP) to access ePO - On-prem.
Go to Services.
Confirm that the ePO - On-prem Event Parser is running. If it has stopped or paused, restart it to resolve the issue.
Setting up remote log servers
Logging information is sent to the local syslog, and one or more remote logging servers if you have them enabled. Syslog entries contain information about the device itself (the vendor, product name, and version), the severity of the event, and the date the event occurred. Use Logging settings in the General category of the Policy Catalog → Common Appliance Management policy to set up remote logging servers.