Missing incident creation when uploading multiple files
search cancel

Missing incident creation when uploading multiple files

book

Article ID: 251632

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

When customer is uploading multiple files on "dlptest.com", all files are getting blocked as expected, but incidents are not generated for all files.

For example, if customer uploads 7 files on "dlptest.com" (HTTPS upload), all files get blocked as per policy, but only 4 incidents are generated instead of 7 incidents.

Customer is uploading 7 files with different filenames and file sizes. File type matching and Protocol matching rules are present in concerned policy.

Environment

DLP 15.8

 

Resolution

This is a website specific issue for "dlptest.com". This issue is not observed on other websites like "gmail.com" or "box.com".

"dlptest.com" doesn't try to upload multiple files at once, if the earlier files are blocked. So, subsequent files are not uploaded . Hence, DLP agent won't get detection request for all files for "dlptest.com".