DLP Agent Upgrade and Migration to a New Enforce Environment
search cancel

DLP Agent Upgrade and Migration to a New Enforce Environment

book

Article ID: 419350

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention Core Package Data Loss Prevention Endpoint Prevent

Issue/Introduction

You are attempting to upgrade the DLP agent using an installation package that was generated on a different Enforce server.

Environment

You currently have an environment running older software with DLP agents managed by the legacy Enforce server. A new Enforce instance has been deployed alongside this environment, and the objective is to upgrade the agents and transition them to the new environment using installation packages generated on the new Enforce server.

Cause

This approach is not the recommended method for upgrading and switching environments. Proceeding in this manner may lead to various issues with Agent task and incident processing, caused by stale (old) state objects coming from the legacy environment remaining in the Agent's local databases. For example, incidents generated by policies from the legacy Enforce may remain in the Agent’s is.ead database and the Agent will attempt to replicate them to the Endpoint Server when it attempts to connect to the new environment. These incidents will then fail to persist on the new Enforce and database, because the new environment is missing references to legacy policies that generated the incidents on the legacy environment.

Resolution

To perform an Agent upgrade combined with a move between DLP infrastructures, please uninstall the Agent associated with the legacy environment and perform a fresh installation using the package generated for the new environment. A direct upgrade approach for the upgrade+move combination is not supported.