Hi all.
I need a help with a issue that I'm struggling some days.
I installed in my lab a DLP enviroment that has two server, one Enforce and other Endpoint Prevent.
After, I installed in a Windows 7 x64 Machine the DLP Agent and it is possible to check through the Enforce Console that this agent is working very well but I can't block or notify users about sensitive files.
Any policy that I sent to Agent didn't work and after many tests I discovered some warning in the Agent log.
I appreciate any support about this issue.
08/08/2014 14:22:58 | 2840 | WARNING | GlobalDataIdentifierMatcher | Condition [-501] will not be evaluated because Identifier [[Identifier:51, Breadth:101]] could not be found
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 08/08/2014 17:22:58 [req#2061 FAILURE Failed to retrieve Global DataIdentifier no incidents]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 08/08/2014 17:22:58 [
Request Id #2061 FAILURE Failed to retrieve Global DataIdentifier allow
Scan Time : 3 ms]
08/08/2014 14:22:58 | 3548 | WARNING | InternetExplorer.IEConnector | Analyze Failed. Error Code:0x8001ffff
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_REQUEST MESSAGESOURCE_IE_CONNECTOR 08/08/2014 17:22:58 [
Request Id #2068
Detection Request Details :
Session Command : Session Continue Request
Session Id : {3B7E2265-2BB8-466D-A0FB-9773AF06E159}
Request Type : Data In Motion Request
Dim Detection Request Details :
Process Id : 2948
Process Path : C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Application Name : Microsoft Internet Explorer
User : esouza
Domain : WIN-F09QVUPRDU2
Time Stamp : 08/08/2014 17:22:58
Dim Event Type : HTTP(S)
HTTP(S) Details :
URL : https://br-mg5.mail.yahoo.com/ws/mail/v2.0/jsonrpc...
Network Info Details :
Source IP :
Source Port : 0
Source Domain :
Destination IP :
Destination Port : 0
Destination Host Name : br-mg5.mail.yahoo.com
]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_SCHEDULE_DETECTION MESSAGESOURCE_DETECTION_CACHE 08/08/2014 17:22:58 [req#2068 CrackingProcessPriority=NORMAL]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_START_DETECTION MESSAGESOURCE_DETECTION_SCHEDULER 08/08/2014 17:22:58 [req#2068 CrackingProcessPriority=NORMAL]
08/08/2014 14:22:58 | 2840 | WARNING | GlobalDataIdentifierMatcher | Condition [-501] will not be evaluated because Identifier [[Identifier:51, Breadth:101]] could not be found
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 08/08/2014 17:22:58 [req#2068 FAILURE Failed to retrieve Global DataIdentifier no incidents]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 08/08/2014 17:22:58 [
Request Id #2068 FAILURE Failed to retrieve Global DataIdentifier allow
Scan Time : 15 ms]
08/08/2014 14:22:58 | 3548 | WARNING | InternetExplorer.IEConnector | Analyze Failed. Error Code:0x8001ffff
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_REQUEST MESSAGESOURCE_IE_CONNECTOR 08/08/2014 17:22:58 [
Request Id #2073
Detection Request Details :
Session Command : Session Close Request
Session Id : {3B7E2265-2BB8-466D-A0FB-9773AF06E159}
]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_SCHEDULE_DETECTION MESSAGESOURCE_DETECTION_CACHE 08/08/2014 17:22:58 [req#2073 CrackingProcessPriority=NORMAL]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_START_DETECTION MESSAGESOURCE_DETECTION_SCHEDULER 08/08/2014 17:22:58 [req#2073 CrackingProcessPriority=NORMAL]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 08/08/2014 17:22:58 [req#2073 SUCCESS no incidents]
08/08/2014 14:22:58 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 08/08/2014 17:22:58 [
Request Id #2073 SUCCESS allow
Scan Time : 15 ms]
08/08/2014 14:25:28 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_USER_ACTIVITY MESSAGESOURCE_UIPROXY 08/08/2014 17:25:28 [All users are idle]
08/08/2014 14:31:15 | 3964 | ADMIN | AgentServices.SystemEventLogger | Category: agent_event.category.troubleshooting_task_status, SubCategory: agent_event.subcategory.pull_logs_task_succeeded, Extended Value: 1151;Pull Log Task is Completed
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_REQUEST MESSAGESOURCE_CLIPBOARD_CONNECTOR 08/08/2014 19:43:38 [
Request Id #2128
Detection Request Details :
Session Command : Single Request
Request Type : Data In Motion Request
Dim Detection Request Details :
Process Id : 856
Process Path : C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
Application Name : VMware Tools
User : esouza
Domain : WIN-F09QVUPRDU2
Time Stamp : 08/08/2014 19:43:38
Dim Event Type : Clipboard
Clipboard Details :
Application Name : Administrator: C:\Windows\System32\cmd.exe
]
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_SCHEDULE_DETECTION MESSAGESOURCE_DETECTION_CACHE 08/08/2014 19:43:38 [req#2128 CrackingProcessPriority=NORMAL]
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_START_DETECTION MESSAGESOURCE_DETECTION_SCHEDULER 08/08/2014 19:43:38 [req#2128 CrackingProcessPriority=NORMAL]
08/08/2014 16:43:38 | 2840 | WARNING | GlobalDataIdentifierMatcher | Condition [-501] will not be evaluated because Identifier [[Identifier:51, Breadth:101]] could not be found
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 08/08/2014 19:43:38 [req#2128 FAILURE Failed to retrieve Global DataIdentifier no incidents]
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 08/08/2014 19:43:38 [
Request Id #2128 FAILURE Failed to retrieve Global DataIdentifier allow
Scan Time : 31 ms]
08/08/2014 16:43:38 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_USER_ACTIVITY MESSAGESOURCE_UIPROXY 08/08/2014 19:43:38 [User activity detected]
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_FILE_OP_ADDREMOVE_REQUEST MESSAGESOURCE_FILEOPERATION_CONNECTOR 08/08/2014 19:43:47
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_REQUEST MESSAGESOURCE_FILEOPERATION_CONNECTOR 08/08/2014 19:43:47 [
Request Id #2138
Detection Request Details :
Session Command : Single Request
Request Type : Data In Motion Request
Dim Detection Request Details :
Process Id : 2284
Process Path : C:\Windows\Explorer.EXE
Application Name : Microsoft® Windows® Operating System Windows Explorer
User : esouza
Domain : WIN-F09QVUPRDU2
Time Stamp : 08/08/2014 19:43:47
Dim Event Type : File System
DIM File Detection Request Details :
file: C:\Users\esouza\Desktop\cartao.txt
]
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_SCHEDULE_DETECTION MESSAGESOURCE_DETECTION_CACHE 08/08/2014 19:43:47 [req#2138 CrackingProcessPriority=NORMAL]
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_START_DETECTION MESSAGESOURCE_DETECTION_SCHEDULER 08/08/2014 19:43:47 [req#2138 CrackingProcessPriority=NORMAL]
08/08/2014 16:43:47 | 2840 | WARNING | GlobalDataIdentifierMatcher | Condition [-501] will not be evaluated because Identifier [[Identifier:51, Breadth:101]] could not be found
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 08/08/2014 19:43:47 [req#2138 FAILURE Failed to retrieve Global DataIdentifier no incidents]
08/08/2014 16:43:47 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 08/08/2014 19:43:47 [
Request Id #2138 FAILURE Failed to retrieve Global DataIdentifier allow
Scan Time : 46 ms]
08/08/2014 16:46:10 | 1792 | INFO | CoreServices.MessageLogger | MESSAGETYPE_USER_ACTIVITY MESSAGESOURCE_UIPROXY 08/08/2014 19:46:10 [All users are idle]