DLP Discover scan failed with code 3707
search cancel

DLP Discover scan failed with code 3707

book

Article ID: 258680

calendar_today

Updated On:

Products

Data Loss Prevention Network Discover Data Loss Prevention Data Loss Prevention Enforce

Issue/Introduction

Enforce Console > Manage > Discover Scanning > Discover Targets shows a failed scan status.


The Discover Server shows event code 3707 - Scan failed: Remediation detection catalog could not be updated

When attempting to run a new scan from the Enforce console, using the same Discover Server, you may see the following  error message

"Failed to contact the scan manager. Make sure Symantec DLP Detection Server Controller service is running."

Environment

Data Loss Prevention 15.8 x

Data Loss Prevention 16.x

Cause

From the FileReader log:

com.vontu.discover.fsm.StateMachine catalogUnavailable
INFO: Remediation detection catalog update timed out after 1,800,000 seconds for target <Discover scan name>

Resolution

  1. From Enforce, ensure all scans targeting the impacted Detection Server are stopped.
  2. Stop the SymantecDLPDetectionServerController service on the Enforce Server.
  3. From the Detection Server, stop SymantecDLPDetectorService.
    • For 16.0 servers, stop SymantecDLPDetectionServerService.
  4. On the same Detection Server go to the following directory (this is the default path but will vary depending on where DLP is installed).

    Windows: \ProgramData\Symantec\DataLossPrevention\DetectionServer\<dlp version>\scan\catalog 
    Linux: /var/Symantec/DataLossPrevetion/DetectionServer/<dlp version>/scan/catalog

  5. Take a backup of RemediationResiliencyStorage folder (copy entire folder in a backup folder outside of where DLP is installed)
  6. Delete the RemediationResiliencyStorage folder from catalog folder.
  7. Start the Detection Server Services: SymantecDLPDetectorService or SymantecDLPDetectionServerService
  8. Start SymantecDLPDetectionServerController on the Enforce Server.
  9. Restart the Discover Scan.