Incidents are Deleted When The Folder Maximum Capacity is Met
book
Article ID: 378586
calendar_today
Updated On:
Products
Data Loss PreventionData Loss Prevention API Detection for Developer Apps Virtual ApplianceData Loss Prevention API Detection Virtual ApplianceData Loss Prevention Cloud Detection ServiceData Loss Prevention Cloud Detection Service for ICAPData Loss Prevention Cloud Detection Service for RESTData Loss Prevention Cloud PackageData Loss Prevention Cloud Prevent for Microsoft Office 365Data Loss Prevention Cloud Service for Discovery/ConnectorData Loss Prevention Cloud Service for EmailData Loss Prevention Cloud StorageData Loss Prevention Core PackageData Loss Prevention Data Access GovernanceData Loss Prevention Discover SuiteData Loss Prevention Endpoint DiscoverData Loss Prevention Endpoint PreventData Loss Prevention Endpoint SuiteData Loss Prevention EnforceData Loss Prevention Enterprise SuiteData Loss Prevention for MobileData Loss Prevention for Office 365 Email and Gmail with Email SafeguardData Loss Prevention Form RecognitionData Loss Prevention Network DiscoverData Loss Prevention Network EmailData Loss Prevention Network MonitorData Loss Prevention Network Monitor and Prevent for EmailData Loss Prevention Network Monitor and Prevent for Email and WebData Loss Prevention Network Monitor and Prevent for WebData Loss Prevention Network Prevent for EmailData Loss Prevention Network Prevent for Email Virtual ApplianceData Loss Prevention Network Prevent for Web Virtual ApplianceData Loss Prevention Network ProtectData Loss Prevention Network WebData Loss Prevention Oracle Standard Edition 2Data Loss Prevention Plus SuiteData Loss Prevention Sensitive Image Recognition
Issue/Introduction
For File System - High Speed Discovery and Cloud Detection Server detection, when the incident folder on the Enforce Server reaches maximum capacity (as indicated in max_incidents_in_folder in MonitorController.properties),
The next incident that goes above the max_in_incidents_folder will be dropped. The monitor controller will block any new incidents from being transmitted so that they can be replicated later. The Monitor Controller process checks every 10 secs and if the number of files is lower than the max_in_incidents_folder value, then the monitor controller will accept incidents to be replicated again.
Environment
Discover File System - High Speed Discovery and Cloud Detection Server Scans
Resolution
Hotfixes available to download for the following versions:
16.0 MP2, 16.0 RU1, 16.0 RU2
WORKAROUND:
Increase the value listed at max_incidents_in_folder in MonitorController.properties.
Additional Information
Broadcom is aware of the issue and is working on a hotfix for 15.8 mp3 will be released soon.