Discover scans of MSG or EML files results in duplicate incidents

book

Article ID: 160238

calendar_today

Updated On:

Products

Data Loss Prevention Network Discover

Issue/Introduction

Discover decomposes MSG, EML files into two files (MSG and MAIL).

Resolution

Relevant versions:  6.0 and above

Discover scans of .msg, .eml files results in duplicate incidents that have the exact same ID and content.

The root cause is a known bug reported in PROTECT-6717 (Etrack 1309882; 1309883; 1309884), which causes .msg (.eml) messages to decompose into .msg (.eml) and .MAIL files. This results in duplicate scanning of the content.

This happens both at scanning a *.msg, *.eml file on a file system and during a PST scanning.