Antivirus software running on the same system as Symantec DLP and may or may not be flagging it as a virus or a security threat.
You want to exclude DLP files from being scanned by antivirus software.
This article covers exclusions for DLP servers; for Agents, see Best Practice: Endpoint Agents with Antivirus Protection (broadcom.com)
Symantec Data Loss Prevention (DLP) frequently writes to several common directories. Some antivirus solutions may view this behavior like a virus or security threat and may interfere with DLP processes - having unexpected results.
See also this summary for why this is necessary:
About Symantec Data Loss Prevention and antivirus software (broadcom.com)
In general, in your antivirus software, you should exclude or omit the following directories from future scans.
\ProgramData\Symantec\DataLossPrevention\EnforceServer\<version>\logs (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\EnforceServer\<version>\scan (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\EnforceServer\<version>\tomcatTemp
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\incidents (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\index
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\scan (with subdirectories)
\Program Files\Symantec\DataLossPrevention\EnforceServer\<version>\Protect\tomcat
\Program Files\Symantec\DataLossPrevention\EnforceServer\<version>\Protect\tomcat\work
Where <version> is the Enforce Server version you are running, e.g., 16.0.00000.
\ProgramData\Symantec\DataLossPrevention\DetectionServer\<version>\drop (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\DetectionServer\<version>\logs (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\DetectionServer\<version>\scan (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\DetectionServer\<version>\spool (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\DetectionServer\<version>\temp (with subdirectories)
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\incidents
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\index
\ProgramData\Symantec\DataLossPrevention\ServerPlatformCommon\<version>\scan (with subdirectories)
\Program Files\Symantec\DataLossPrevention\DetectionServer\Services
Where <version> is the Detection Server version you are running, e.g., 16.0.00000.
\app\Administrator\oradata\protect
\app\Administrator\product\<version>\dbhome_1
Where <version> is the Oracle software version you are running.
Most of the Oracle files to be excluded are located in these directories, but additional files are located in other directories.
Use the Oracle Enterprise Manager (OEM) to check for additional files and exclude their directories from antivirus scanning.
Use OEM to view the location of the following database files:
\ProgramData\Symantec\DataLossPrevention\OCRServer\<version>
\ProgramData\OmniPage
\SymantecDLPOCR
Where OCR Server version you are running, e.g., 16.0.00000.
Note: Symantec does not recommend that you exclude individual binaries from antivirus applications. The names and locations of binary files may change with new software releases and patches. Additionally, we also create and place files in directories like drop, drop_pcap, etc. Since we do not know what the file names will be, we must exclude the entire directory.