The Trellix DLP Network Monitor – SaaS system health cards display information about appliance type, system health, and analysis statistics.
System health cards display Trellix DLP Network Monitor – SaaS as Monitor Server. Each functioning appliance is shown as Active. An appliance can be one of the following types, depending on whether it is configured as a standalone appliance or as a member of a cluster:
Monitor Server Standalone
Monitor Cluster Packet Acquisition Device
Monitor Cluster Primary Appliance
Monitor Cluster Scanner
Status is displayed in green, amber, or red. The status color depends on whether warning and critical threshold values are exceeded, or there is an error. More information is provided in the Alerts and Details panes.
Trellix DLP Network Monitor – SaaS statistics
In addition to the standard system health information about each appliance or cluster of appliances, you can see the following information:
Evidence Queue — Shows the number of evidence files waiting to be copied to evidence storage.
If the total combined size of the items in the queue exceeds a threshold, an alert is issued. If the evidence server is unavailable because, for example, it can't be contacted, the evidence is queued until the server becomes available again.
The queue has between 20–200 GB storage available, depending on the platform. If it becomes full, no further incidents are created.
This statistic does not apply to a packet acquisition device.
CPU — Displays information about CPU usage: % busy, % system, % user, % idle.
Memory — Displays information about memory used, swap use, and swap rate.
Disk — Disk state is added for each filesystem. A non-zero value is a faulty state and will show different alerts based on different state values.
Network — Displays the information about received and transmitted data. For capture1, the following details are displayed:
Packets per second — The number of packets processed by Trellix DLP Network Monitor – SaaS standalone appliance or a cluster packet acquisition device every second.
Packet drops — The number of packets dropped at the network interface.
Monitor — Monitors the following information (these statistics apply to a standalone appliance and a cluster packet acquisition device):
Active flows — The current number of conversations on your network tracked by the Trellix DLP Network Monitor – SaaS appliance.
Flows filtered — The current number of conversations that are not scanned according to filter rules.
Payloads scanned — Displays the number of payloads analyzed by Trellix DLP Network Monitor – SaaS for each protocol.
Payload scan failure — Displays the number of payloads that can't be analyzed if, for example, an email message is corrupt or the time to analyze the payload exceeds the timeout limit.
Payloads oversize — Displays the number of payloads that exceed the configured limit.
Trellix DLP Network Monitor – SaaS can't analyze partially extracted .zip files.
OCR Scan — When OCR scanning is enabled, images to be scanned are held in a queue. When the queue size exceeds the queue size limit, Trellix DLP Network Monitor – SaaS ignores extra images until the number of pending OCR scans fall below the maximum queue size. This is done to avoid disruption to email and web traffic. When this situation arises, an alert and its details are displayed in the Appliance Management dashboard.
Counters are updated on the appliance every 60 seconds. Apart from the evidence queue counter, the counters are not cumulative.
Trellix DLP Network Monitor – SaaS alerts
The evidence queue exceeded the default threshold.
The payload could not be analyzed.
Trellix DLP Network Monitor – SaaS could not enforce a policy.
The virtual IP address that you assigned is not on the same subnet or network as Trellix DLP Network Monitor – SaaS.
ePO - SaaS could not contact Trellix DLP Network Monitor – SaaS (for example, if the power supply was interrupted).
An alert is not generated if the appliance was shut down manually.