Viewing Trellix DLP Network Prevent health information in ePO - On-prem

Prev Next

The Trellix DLP Network Prevent system health cards display information about system type, system health, email and web statistics, and the evidence queue.

System health cards display Trellix DLP Network Prevent system as Prevent Server, and each functioning system is shown as Active. A Trellix DLP Network Prevent system can be one of the following types, depending on whether it is standalone or part of a cluster:

  • Prevent Server Standalone

  • Prevent Server Cluster Primary Appliance

  • Prevent Server Cluster Scanner

The status is displayed in green, amber, or red and the status appears as grayed-out if the parameter isn't applicable to the Trellix DLP Network Prevent system. The status color depends on whether warning and critical threshold values have exceeded, or if there is an error. The status value (such as 0, 1, usage %, OK, or OFF) that is shown at the end of the graph, is most latest status. More information is provided in the Alerts and Details panes to analyze any error and troubleshoot the error accordingly.

Note

The line graphs show the health status for the last 24 hours. You can see the last refreshed time at the top of the System Health card. To see the latest status, refresh the browser. For optimal performance of the system, the interval between the data points is four minutes.

Trellix DLP Network Prevent statistics

In addition to standard system health information about each Trellix DLP Network Prevent system or cluster of Trellix DLP Network Prevent systems, you can see the following information:

  • Evidence Queue — Shows the number of evidence files waiting to be copied to evidence storage. If the evidence server is unavailable, for example, it can't be contacted, the evidence is queued until the server becomes available again. If the total combined size of the items in the queue exceeds a threshold, an alert is issued.

    The evidence queue storage limit varies based on the platform and the availability of the storage ranges between 20-200 GB. After the storage reaches its threshold, no further incidents are generated. Any further traffic is refused and an error message is issued.

  • Emails (per minute) — Shows the total number of messages that are processed, includes the delivered, temporarily or permanently rejected messages.

    • A message might be temporarily rejected if, for example, the Smart Host is unavailable.

    • A message might be permanently rejected if, for example, the recipient address is incorrect or the Smart Host blocks the message.

  • Web Requests (per minute) — Shows the total number of web requests that the Trellix DLP Network Prevent system processed in a minute, and the number it could not analyze.

  • Capture — (Optional) The Capture statistics are visible when the DLP Capture feature is enabled on Trellix DLP Network Prevent system. Capture statistics includes:

    • The number of days remaining before the capture storage reaches its capacity

    • The age of the oldest captured item held in the storage

    • The number of searches currently in progress.

  • CPU — Displays information about CPU usage: % busy, % system, % user, % idle.

  • Memory — Displays information about memory used, swap use, and swap rate.

  • Disk — Displays the information about the disk partitions and its usage.

  • OCR Scan — When OCR scanning is enabled, images to be scanned are held in a queue. When the queue size exceeds the threshold limit, Trellix DLP Network Prevent system ignores extra images until the number of pending OCR scans fall below the maximum queue size. This is done to avoid disruption to email and web traffic. When this situation arises, an alert and its details are displayed in the Appliance Management dashboard.

Process States — Helps identify the health status of processes or services that are running in the Trellix DLP Network Prevent system. It shows whether a process is running properly, turned off, or not functioning.

To reduce the load on the Trellix DLP Network Prevent system processes or services, you can configure the interval of health check queries sent to the appliance processes or services or disable the health check queries. For information about how to configure the query interval, see KB96788.

  • Common Process States

    • cma — Shows the status of Common Management Agent (CMA), which is also referred to as Trellix Agent. If CMA is unavailable, the communication between the Trellix DLP Network Prevent and ePO - On-prem fails.

    • crond — Shows the status of crond process. Crond is a background process that runs specified programs at scheduled time.

      If the crond process stops functioning or is turned off on the Trellix DLP Network Prevent system, the execution of cron jobs is affected.

    • evthandler — Shows the status of event handler.

    • incrond — Shows the status of incrond process. Incrond is a background process that monitors any change in the filesystem.

      If this process stops functioning or is turned off on the Trellix DLP Network Prevent system, the execution of jobs is affected when there is a change in the filesystem.

    • mca — Shows the status of the Trellix Common Appliance processes.

      MCA is the Common Appliance agent that is responsible for the exchange of information between Trellix DLP Network and ePO - On-prem. If MCA is unavailable, the communication between Trellix DLP Network Prevent and ePO - On-prem fails.

    • mlcdaemon — Shows the status of Trellix Logon Collector process running in the background.

    • ntp — Shows the status of network time protocol service. Used for clock synchronization.

    • named — Shows the status of the named service. Named is the name of a service used for DNS (Dynamic Name Service) lookups that run in the background.

    • postgres — (Available only when DLP Capture is enabled on Trellix DLP Network Prevent) Shows the status of Postgres.

      Postgres is a database service that is used to store metadata processed by the tmgr service.

    • redis — The status of Redis. Redis is an in-memory database that contains data, which is used by scanning service to determine if the content is unscannable and returns SCANFAIL. It also stores user logon data processed by Trellix Logon Collector.

    • snmpd — (Available only when snmpd is enabled on Trellix DLP Network Prevent) Shows the status of the snmpd service. snmpd is an SNMP agent that binds to a port and awaits requests from SNMP management software. Upon receiving a request, it processes the requests, collects the requested information and/or performs the requested operations, and then returns the information to the sender.

    • tmgr — (Available only when DLP Capture is enabled on Trellix DLP Network Prevent ) Shows the status of task manager service (tmgr).

      Tmgr is a service that receives the capture search requests, processes them, and returns the capture search completion status.

  • Stunnel State

    • stunnel — (Applicable to a cluster of Trellix DLP Network Prevent system) Shows the status of stunnel state. Stunnel converts non-secure TCP connections to secure connections.

  • Prevent Only Process States

    • icap — Shows the status of ICAP service that is running in the Trellix DLP Network Prevent system.

    • smtp — Shows the status of SMTP service that is running in the Trellix DLP Network Prevent system.

  • Other Process States

    • evidenceservice — Shows the status of evidence service.

    • evdmonitor — Shows the status of evidence monitor.

    • scanningservice — Shows the status of scanning service.

See the information about error messages to find out what happens if a message or web request is blocked. Apart from the evidence queue counter, the counters are not cumulative.

Trellix DLP Network Prevent alerts

If a system or process health status appears in amber or red, more information is provided in the Alerts and Details panes. Trellix DLP Network Prevent also provides alert information in the following circumstances.

  • The evidence queue exceeded the default threshold.

  • Trellix DLP Network Prevent could not enforce a policy.

  • The virtual IP address that you assigned is not on the same subnet or network as Trellix DLP Network Prevent.

  • ePO - On-prem could not contact the Trellix DLP Network Prevent system (for example, if the power supply was interrupted).

    An alert is not generated if the Trellix DLP Network Prevent system was shut down manually.

  • If the DLP Capture feature is enabled, alerts are issued when:

    • The Capture partition is corrupt.

    • The password to secure encrypted data needs to be changed.

  • Processes or services running in the Trellix DLP Network Prevent system are not functioning.