Check if an Indexed Document Matching index has been deployed to a Data Loss Prevention detection server
search cancel

Check if an Indexed Document Matching index has been deployed to a Data Loss Prevention detection server

book

Article ID: 164646

calendar_today

Updated On:

Products

Data Loss Prevention Enforce

Issue/Introduction

Whenever there's an issue with a policy that uses Indexed Document Matching (IDM) detection rules, one of the possible reasons may be that the IDM index generated on Enforce has not been successfully deployed to the Detection Server that should be generating the incident. 

Resolution

There are a couple of ways to check if the IDM index has been properly pushed out to the detection server. Follow the steps below:

  1. Log in to Enforce and go to the Manage -> Data Profiles - Indexed Documents. 
  2. Locate your document profile and hover your cursor over the name. In the lower-left corner of your browser, you should see a string that says "javascript:followlink('PreDocumentSourceEdit.do?dataSourceID=someNumber')". The 'someNumber' parameter should be a numerical value. Note it down.
  3. Click on the gray arrow on the left to the index name. This should show you all detection servers and the current status of the index on these servers. The status should be "Completed" with a date of when the index has been successfully pushed out to the server. If the deployment of the index failed, you will see that in the status.
  4. You can also check if the index exists directly on the detection server that should have it by going to the server and checking the path \SymantecDLP\Protect\index. Look for a file named DocSource.someNumber.version.rdx - someNumber is the same number as the one you wrote down in point 2, while version is the version number of the index. If the file is not present, it means the index has not been successfully deployed. 
  5. If the index has not been deployed to one or more detection servers, click on the Retry button placed where the document profile in the Indexed Documents section on Enforce is.