Viewing Trellix DLP Network Prevent – SaaS health information in ePO - SaaS

Prev Next

The Trellix DLP Network Prevent – SaaS system health cards display information about appliance type, system health, email and web statistics, and the evidence queue.

System health cards display Trellix DLP Network Prevent – SaaS as Prevent Server, and each functioning appliance is shown as Active. An appliance can be one of the following types, depending on whether it is standalone or part of a cluster:

  • Prevent Server Standalone

  • Prevent Server Cluster Primary Appliance

  • Prevent Server Cluster Scanner

Status is displayed in green, amber, or red. The status color depends on whether warning and critical threshold values are exceeded, or there is an error. More information is provided in the Alerts and Details panes.

Trellix DLP Network Prevent – SaaS statistics

In addition to standard system health information about each appliance or cluster of appliances, you can see the following information:

  • Evidence Queue — Shows the number of evidence files waiting to be copied to evidence storage. If the total combined size of the items in the queue exceeds a threshold, an alert is issued. If the evidence server is unavailable because, for example, it can't be contacted, the evidence is queued until the server becomes available again.

    The evidence queue has between 20–200 GB storage available, Depending on the platform. If it becomes full, no further incidents are created, any further traffic is refused, and a failure response is issued. For SMTP traffic, this is a temporary failure response. For ICAP traffic, the response is a server failure error.

  • Emails (per minute) — Shows the number of messages that were delivered, were permanently or temporarily rejected, or could not be analyzed.

    • A message might be temporarily rejected if, for example, the Smart Host is unavailable.

    • A message might be permanently rejected if, for example, the recipient address is incorrect or the Smart Host blocks the message.

  • Web Requests (per minute) — Shows the number of web requests that Trellix DLP Network Prevent – SaaS received and the number it could not analyze.

  • CPU — Displays information about CPU usage: % busy, % system, % user, % idle.

  • Memory — Displays information about memory used, swap use, and swap rate.

  • Disk — Disk state is added for each filesystem. A non-zero value is a faulty state and will show different alerts based on different state values.

  • OCR Scan — When OCR scanning is enabled, images to be scanned are held in a queue. When the queue size exceeds the threshold limit, Trellix DLP Network Prevent – SaaS ignores extra images until the number of pending OCR scans fall below the maximum queue size. This is done to avoid disruption to email and web traffic. When this situation arises, an alert and its details are displayed in the Appliance Management dashboard.

See the information about error messages to find out what happens if a message or web request is blocked. Apart from the evidence queue counter, the counters are not cumulative.

Trellix DLP Network Prevent – SaaS alerts

If a system health status appears in amber or red, more information is provided in the Alerts and Details panes. Trellix DLP Network Prevent – SaaS also provides alert information in the following circumstances.

  • The evidence queue exceeded the default threshold.

  • Trellix DLP Network Prevent – SaaS could not enforce a policy.

  • The virtual IP address that you assigned is not on the same subnet or network as Trellix DLP Network Prevent – SaaS .

  • ePO - SaaS could not contact Trellix DLP Network Prevent – SaaS (for example, if the power supply was interrupted).

    An alert is not generated if the appliance is shut down manually.