cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3656
Views
5
Helpful
5
Replies

Retrospective Quarantine Attempt Failed alerts

pavan1989
Level 1
Level 1

Hello,

 

We are observing huge sipke in Retrospective Quarantine Attempt Failed alerts from past 2 days. Also, in the Event types not showing files affected. Could anyone please suggest what could be the issue.

5 Replies 5

ckuwajima
Level 1
Level 1

My experience with retrospective quarantine attempt failed events is that I could not locate the culprit file anywhere in the target system.

In my case, every instance was a file in temporary file directory, probably deleted by OS or application, long before AMP flagged as a compromise.

DaphneG
Cisco Employee
Cisco Employee

@pavan1989, is it happening to one machine only? @ckuwajima is right, it usually happens when the file it's trying to quarantine is no longer found in the same location it was found by the connector originally. But I can't explain the spike without details and logs. The empty file info is strange too. 

Please open a TAC case so it can be investigated. 

Hello @DaphneG 

 

It's showing for all the machines when I see in the event type for the compromised machine the file is empty.

pavan1989
Level 1
Level 1

Hello @DaphneG and @ckuwajima 

 

When I click on File Analysis for the same alert I am observing an error as Tsv Not Enabled Html. Could you please guide me what could be the issue.

Never saw such problem and do not have deep understanding of AMP for Endpoints. You'd better open a TAC case as @DaphneG said.