Incidents are Deleted When The Folder Maximum Capacity is Met
search cancel

Incidents are Deleted When The Folder Maximum Capacity is Met

book

Article ID: 378586

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention API Detection for Developer Apps Virtual Appliance Data Loss Prevention API Detection Virtual Appliance Data Loss Prevention Cloud Detection Service Data Loss Prevention Cloud Detection Service for ICAP Data Loss Prevention Cloud Detection Service for REST Data Loss Prevention Cloud Package Data Loss Prevention Cloud Prevent for Microsoft Office 365 Data Loss Prevention Cloud Service for Discovery/Connector Data Loss Prevention Cloud Service for Email Data Loss Prevention Cloud Storage Data Loss Prevention Core Package Data Loss Prevention Data Access Governance Data Loss Prevention Discover Suite Data Loss Prevention Endpoint Discover Data Loss Prevention Endpoint Prevent Data Loss Prevention Endpoint Suite Data Loss Prevention Enforce Data Loss Prevention Enterprise Suite Data Loss Prevention for Mobile Data Loss Prevention for Office 365 Email and Gmail with Email Safeguard Data Loss Prevention Form Recognition Data Loss Prevention Network Discover Data Loss Prevention Network Email Data Loss Prevention Network Monitor Data Loss Prevention Network Monitor and Prevent for Email Data Loss Prevention Network Monitor and Prevent for Email and Web Data Loss Prevention Network Monitor and Prevent for Web Data Loss Prevention Network Prevent for Email Data Loss Prevention Network Prevent for Email Virtual Appliance Data Loss Prevention Network Prevent for Web Virtual Appliance Data Loss Prevention Network Protect Data Loss Prevention Network Web Data Loss Prevention Oracle Standard Edition 2 Data Loss Prevention Plus Suite Data Loss Prevention Sensitive Image Recognition

Issue/Introduction

For File System - High Speed Discovery and Cloud Detection Server detection, when the incident folder on the Enforce Server reaches maximum capacity (as indicated in max_incidents_in_folder in MonitorController.properties), 

The next incident that goes above the max_in_incidents_folder will be dropped. The monitor controller will block any new incidents from being transmitted so that they can be replicated later. The Monitor Controller process checks every 10 secs and if the number of files is lower than the max_in_incidents_folder value, then the monitor controller will accept incidents to be replicated  again.

Environment

Discover File System - High Speed Discovery and Cloud Detection Server Scans

Resolution

Hotfixes available to download for the following versions:

16.0 MP2, 16.0 RU1, 16.0 RU2

WORKAROUND:

Increase the value listed at max_incidents_in_folder in MonitorController.properties.

 

Additional Information

Broadcom is aware of the issue and is working on a hotfix for 15.8 mp3 will be released soon.