Viewing Trellix DLP Network Monitor appliance health information in ePO - On-prem

Prev Next

The Trellix DLP Network Monitor system health cards display information about appliance type, system health, and analysis statistics.

System health cards display Trellix DLP Network Monitor appliances as Monitor Server. Each functioning appliance is shown as Active. An appliance can be one of the following types, depending on whether it is configured as a standalone appliance or as a member of a cluster:

  • Monitor Server Standalone

  • Monitor Cluster Packet Acquisition Device

  • Monitor Cluster Primary Appliance

  • Monitor Cluster Scanner

The status is displayed in green, amber, or red and the status appears as grayed-out if the parameter isn't applicable to the appliance. The status color depends on whether warning and critical threshold values have exceeded, or if there is an error. The status value (such as 0, 1, usage %, OK, or OFF) that is shown at the end of the graph, is most latest status. More information is provided in the Alerts and Details panes to analyze any error and troubleshoot the error accordingly.

Note

The line graphs show the health status for the last 24 hours. You can see the last refreshed time at the top of the System Health card. To see the latest status, refresh the browser. For optimal performance of the system, the interval between the data points is four minutes.

Trellix DLP Network Monitor statistics

In addition to the standard system health information about each appliance or cluster of appliances, you can see the following information:

  • Evidence Queue — Shows the number of evidence files waiting to be copied to evidence storage. If the evidence server is unavailable, for example, it can't be contacted, the evidence is queued until the server becomes available again. If the total combined size of the items in the queue exceeds a threshold, an alert is issued.

    The evidence queue storage limit varies based on the platform and the availability of the storage ranges between 20-200 GB. After the storage reaches its threshold, no further incidents are generated. Any further traffic is refused and an error message is issued.

    This statistic does not apply to a packet acquisition device.

  • CPU — Displays information about CPU usage: % busy, % system, % user, % idle.

  • Memory — Displays information about memory used, swap use, and swap rate.

  • Disk — Displays the information about the disk partitions and its usage.

  • Network — Displays the information about the received and transmitted data through the capture1 port. For the capture1 port, the following details are displayed:

    • Packets per second — The number of packets processed by Trellix DLP Network Monitor standalone appliance or a cluster packet acquisition device every second.

    • Packet drops — The number of packets dropped at the network interface.

  • Monitor — Monitors the following information (these statistics apply to a standalone appliance and a cluster packet acquisition device):

    • Active flows — The current number of conversations on your network tracked by the Trellix DLP Network Monitor appliance.

    • Flows filtered — The current number of conversations that are not scanned according to filter rules.

    • Payloads scanned — Displays the number of payloads analyzed by Trellix DLP Network Monitor for each protocol.

    • Payload scan failure — Displays the number of payloads that can't be analyzed if, for example, an email message is corrupt or the time to analyze the payload exceeds the timeout limit.

    • Payloads oversize — Displays the number of payloads that exceed the configured limit.

      Trellix DLP Network Monitor can't analyze partially extracted .zip files.

  • Capture — (Optional) The Capture statistics are visible when the DLP Capture feature is enabled on the appliance. Capture statistics includes:

    • The number of days remaining before the capture storage reaches its capacity

    • The age of the oldest captured item held in the storage

    • The number of searches currently in progress.

  • OCR Scan — When OCR scanning is enabled, images to be scanned are held in a queue. When the queue size exceeds the queue size limit, Trellix DLP Network Monitor appliance ignores extra images until the number of pending OCR scans fall below the maximum queue size. This is done to avoid disruption to email and web traffic. When this situation arises, an alert and its details are displayed in the Appliance Management dashboard.

Process States — Helps identify the health status of processes or services that are running in the appliance. It shows whether a process is running properly, turned off, or not functioning.

To reduce the load on the appliance processes or services, you can configure the interval of health check queries sent to the appliance processes or services or disable the health check queries. For information about configuring the query interval, see KB96788.

  • Common Process States

    • cma — Shows the status of Common Management Agent (CMA), which is also referred to as Trellix Agent. If CMA is unavailable, the communication between the appliance and ePO - On-prem fails.

    • crond — Shows the status of crond process. Crond is a background process that runs specified programs at scheduled time.

      If the crond process stops functioning or is turned off on the appliance, the execution of cron jobs is affected.

    • evthandler — Shows the status of event handler.

    • incrond — Shows the status of incrond process. Incrond is a background process that monitors any change in the filesystem.

      If this process stops functioning or is turned off on the appliance, the execution of jobs is affected when there is a change in the filesystem.

    • mca — Shows the status of the Trellix Common Appliance processes.

      MCA is the Common Appliance agent that is responsible for the exchange of information between Trellix DLP Network and ePO - On-prem. If MCA is unavailable, the communication between the appliance and ePO - On-prem fails.

    • mlcdaemon — Shows the status of Trellix Logon Collector process running in the background.

    • ntp — Shows the status of network time protocol service. Used for clock synchronization.

    • named — Shows the status of the named service. Named is the name of a service used for DNS (Dynamic Name Service) lookups that run in the background.

    • postgres — (Available only when DLP Capture is enabled on appliances.) Shows the status of Postgres.

      Postgres is a database service that is used to store metadata processed by the tmgr service.

    • redis — Shows the status of Redis. Redis is an in-memory database that contains data, which is used by scanning service to determine if the content is unscannable and returns SCANFAIL. It also stores user logon data processed by Trellix Logon Collector.

    • snmpd — (Available only when snmpd is enabled on appliances.) Shows the status of the snmpd service. snmpd is an SNMP agent that binds to a port and awaits requests from SNMP management software. Upon receiving a request, it processes the requests, collects the requested information and/or performs the requested operations, and then returns the information to the sender.

    • tmgr — (Available only when DLP Capture is enabled on appliances.) Shows the status of task manager service (tmgr).

      Tmgr is a service that receives the capture search requests, processes them, and returns the capture search completion status.

  • Stunnel State

    • stunnel — (Applicable to a cluster of appliances.) Shows the status of stunnel state. Stunnel converts non-secure TCP connections to secure connections.

  • Monitor Only Process States

    • dpi — Shows the status of Deep Packet Inspection (DPI) service. DPI is a service used to inspect data packets in IP networks.

  • Other Process States

    • evidenceservice — Shows the status of evidence service.

    • evdmonitor — Shows the status of evidence monitor.

    • scanningservice — Shows the status of scanning service.

Counters are updated on the appliance every 60 seconds. Apart from the evidence queue counter, the counters are not cumulative.

Trellix DLP Network Monitor alerts

If a system or process health status appears in amber or red, more information is provided in the Alerts and Details panes. Trellix DLP Network Monitor also provides alert information in the following circumstances.

  • The evidence queue exceeded the default threshold.

  • The payload could not be analyzed.

  • Trellix DLP Network Monitor could not enforce a policy.

  • The virtual IP address that you assigned is not on the same subnet or network as the Trellix DLP Network Monitor appliance.

  • ePO - On-prem could not contact the Trellix DLP Network Monitor appliance (for example, if the power supply was interrupted).

    An alert is not generated if the appliance was shut down manually.

  • If the DLP Capture feature is enabled, alerts are issued when:

    • The Capture partition is corrupt.

    • The password to secure encrypted data needs to be changed.

  • Processes or services running in the appliance are not functioning.