Network Prevent for Web does not generate incidents
book
Article ID: 160012
calendar_today
Updated On:
Products
Data Loss Prevention Network Prevent for Web
Show More
Show Less
Issue/Introduction
A keyword policy with a compound detection rule, Keyword+Protocol Monitoring for HTTP/HTTPS, does not generate incidents.
Resolution
Ensure that the policy is set to Active.
Confirm the policy group name, and ensure the Keyword+Protocol policy is assigned to the correct policy group.
Check if the Detection Server has been assigned to the policy group required to load the Keyword+Protocol policy.
Review the Detection Server events for "1200 Loaded policy" or "1201 Loaded policies {0.EN_US}" to confirm that the policy had been loaded.
Enable Detection Operational Trace logging (System > Servers > Logs > Configuration tab)
Refer to Configuring Server Logging Behavior (broadcom.com) for additional information.
Submit the test data to an external web site where traffic will be intercepted by a web proxy with Network Prevent for Web attached.
Review 'detection operational trace' logs and ensure that the Detection Server is accurately detecting the sensitive data and triggering incident creation.
Feedback
thumb_up
Yes
thumb_down
No