The Incident history does not update right away when a smart response rule is triggered
search cancel

The Incident history does not update right away when a smart response rule is triggered

book

Article ID: 159638

calendar_today

Updated On:

Products

Data Loss Prevention Network Prevent for Web

Issue/Introduction

When a smart response rule is being trigger via the Enforce UI the Incident history does not reflect this right away.

For example, if an e-mail notification response rule is triggered manually, it takes some time to show within the incident that the email has been sent.

Resolution

The Symantec DLP UI does handle response rules by executing them in the background.
Response rule actions will be added to a background queue and once the response rule has been executed the incident history will reflect this. 
As a result, the observed behavior is expected and can occur when you experience high CPU usage or a larger queuing. 

Another cause of the delay can be if you have email notification performed via an MTA that has high latency.