When running the EDR Capture Forensic Data command on the Device -> Details page in ICDm, you may see the message.
Command '{5A66DC98-F75A-4049-BBFF-8E82D12ED489}' rejected (error: ERROR_UNKNOWN)
On the Device where the command was ran, if you click on the Search Status tab, you'll see an error:
Error An unknown error occurred while performing the search request.
Symantec Endpoint Security
This will be addressed in a future release.