Following a successful upgrade of the Symantec Data Loss Prevention (DLP) environment from version 16.x to 25.1, you may observe a critical failure in detection. Policies utilizing Data Identifiers (DI) fail to perform detection.
DLP 25.1
This issue is caused by a defect introduced during the environment upgrade
To resolve this issue, you must identify the duplicate IDs, clean the affected Data Identifiers (DIs), and force a clean policy deployment.
Follow these steps:
Step 1: Identify Impacted Data Identifiers:
Run a diagnostic SQL query against the Enforce database to locate the duplicate validator IDs.
Note: Please contact Broadcom Support to obtain the diagnostic script.
Step 2: Clean the Affected Identifiers:
For every Data Identifier flagged by the diagnostic script, perform one of the following:
- For Custom DIs: Open the DI configuration in the Enforce Console, remove the custom script validator, and click Save.
- For System-Defined DIs: Delete the corrupted system DI and re-import it from a fresh, "clean" DLP 25.1 environment to ensure correct ID assignment.
Step 3: Rebuild and Deploy:
Manually Re-add Validators: Edit your Custom DIs and manually paste the script text back in. Do not use the policy export/import feature, as this can reintroduce the duplicate IDs.
Force Replication: Save your changes and push the policy. This forces the Enforce server to send a clean, corrected policy package to your Detection Servers.
Step 4: Verify the Fix:
Perform a test detection to confirm that the Detection Server is now correctly performing detection.