Total Incident Screen in Scan Detail is less than Current Incident Count
search cancel

Total Incident Screen in Scan Detail is less than Current Incident Count

book

Article ID: 162255

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Discover

Issue/Introduction

The Scan Detail page shows “Total Detected Incident Count” and “Current Incident Count”.  
The Total Detected and Current Incident Counts do not match after a completed target scan, and the Current Incident Count is larger than the Total Detected Incident Count.

According to the online help documentation, the Current Incident Count (CIC) ought to be the Total Detected Incident Count (TDIC) less deleted incidents, therefore should always be lower than Total Detected Incident Count.
 

Cause

When comparing two scans together (i.e., Incident Count 307 vs. 1), the one with 307 has two items as FILTERED_ITEM.
Exact same items are set as COMPLETED_ITEM in the scan with IncidentCount=1 while every other item there is set as FILTERED_ITEM.
The last scan with Incident Count=1 scans only the items that had been filtered out in the previous scan with Incident Counts = 307.

Extracted from log files are the lines where we see two items filtered out.
Scan IncidentCount=307
"Apr 30, 2015 9:56:23 AM","INFO","[MACH_NAME] 04/30/15 - 7:40 AM","FILTERED_ITEM","//hkn15f2/u_t1193399812/[scan]/vontutest2/vontutest2-30hits.rar","0","Exclude Path Filter","","",""
"Apr 30, 2015 9:56:23 AM","INFO","[MACH_NAME] 04/30/15 - 7:40 AM","FILTERED_ITEM","//hkn15f2/u_t1193399812/[scan]/vontutest2/vontutest2-6hits.rar","0","Exclude Path Filter","","",""
 
The exact same items filtered out in the previous scan, are the only ones logged as COMPLETED_ITEM, while everything else there is marked as FILTERED_ITEM. 
Scan IncidentCount=1: 
"Apr 30, 2015 10:39:32 AM","INFO","[MACH_NAME] 04/30/15 - 10:34 AM","COMPLETED_ITEM","//hkn15f2/u_t1193399812/[scan]/vontutest2/vontutest2-30hits.rar", … 
"Apr 30, 2015 10:40:02 AM","INFO","[MACH_NAME] 04/30/15 - 10:34 AM","COMPLETED_ITEM","//hkn15f2/u_t1193399812/[scan]/vontutest2/vontutest2-6hits.rar", …​

Resolution

This can occur due to items being marked as FILTERED_ITEM, a result of an paused scan.
The Total Detected Incident Count (TDIC) is calculated from the total items touched in a scan.  If a file location is rescanned after a paused scan, items marked as FILTERED_ITEM are skipped from the previous portion of the scan.