Trouble Shooting and Endpoint
Trouble Shooting and Endpoint
System Engineer
Lab Guide 3
Troubleshooting DLP
March 2023
Public
forcepoint.com
© 2023 Forcepoint. Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.
All other trademarks used in this document are the property of their respective owners.
This document may not, in whole or in part, be copied, photocopied, reproduced, translated, or
reduced to any electronic medium or machine-readable form without prior consent in writing
from Forcepoint. Every effort has been made to ensure the accuracy of this manual. However,
Forcepoint makes no warranties with respect to this documentation and disclaims any implied
warranties of merchantability and fitness for a particular purpose.
Forcepoint shall not be liable for any error or for incidental or consequential damages in
connection with the furnishing, performance, or use of this manual or the examples herein. The
information in this documentation is subject to change without notice.
8 Troubleshooting DLP............................................................................................................ 7
8.1 Identifying Forcepoint DLP logs ...................................................................................... 7
8.1.1 Locate DLP Manager configuration files. ............................................................. 7
8.1.2 Enable debugging ................................................................................................ 7
8.1.3 Analyze log files ................................................................................................... 8
8.1.4 Disable debugging ............................................................................................... 8
8.1.5 Using DLPServerInfo tool .................................................................................... 8
8.2 Troubleshooting incidents not appearing in dashboard ................................................ 11
8.2.1 Clear DLP UI (tomcat) and Batch Server (jetty) caches .................................... 11
8.2.2 View the old log files .......................................................................................... 12
8.3 Troubleshooting a hanging discovery task.................................................................... 13
8.3.1 Locate a discovery job ID .................................................................................. 13
8.3.2 Delete a discovery job ....................................................................................... 13
Host: Protector
Host: MRSVR
eth0: 192.168.123.191
IP: 192.168.123.159
eth1: 192.168.123.192
OS: Windows Server 2019
Host: Web_Proxy
Host: DLP_Analytics
IP: 192.168.123.152
IP: 192.168.123.194
OS: CentOS
OS: CentOS
Host: Test_PC
IP: 192.168.123.107
These are the credentials that you will use during your training.
FSM server
Domain: Fpcert
Username: Administrator
Password: Forcepoint1!
Protector
Username: root
Password Forcepoint1!
Your organization needs to create a test machine and wish to copy all the current policies from
the production system but are you unsure if the export process is working. You need to check
the process by enabling logging.
Tasks:
4. Remove the ‘#’ from the beginning of each of the lines starting ‘logger.com’ and save the
file.
4. Exit Notepad++.
DLPServerInfo.log is created under the same folder. Each time the script is run, this folder is
removed and re-created.
Your Forcepoint DLP UI appears to be giving inconsistent results, and incidents are not
appearing.
Tasks:
6. When the script has completed successfully, close Windows Power Shell and reboot the
Security Manager.
Your environment has a very large amount data to scan through and a Discovery Job is seen to
be hanging. Troubleshoot the issue.
Tasks:
You have recently installed F1E but some of the endpoints are not blocking data in the way you
expect. You need to troubleshoot the issue.
Tasks:
You have noticed that some policies are not being triggered on endpoint. Collect log information
to assist troubleshooting the issue.
Tasks:
3. Click Collect Endpoint Info button. The script progress will display.
This folder can be provided to Forcepoint Technical Support to assist them with troubleshooting
any issues.
You have configured your DLP environment and now need to ensure that in the event of a
disaster that you are able to recover your DLP data and configuration without loss to business
operations.
Tasks:
You have your DLP backup folder and want to restore your system in the new DLP
environment.
Tasks:
3. On the Modify Installation window, for Forcepoint DLP, click the Modify link. The
Forcepoint DLP Installer opens.