Configure Email DLP Alert Settings
Focus
Focus
Enterprise DLP

Configure Email DLP Alert Settings

Table of Contents

Configure Email DLP Alert Settings

Configure thresholds and notification recipients so Enterprise Data Loss Prevention (E-DLP) sends your team an email alert when delivery failures, queue backlogs, or scan latency exceed acceptable limits.
Where Can I Use This?What Do I Need?
  • Data Security
  • One of the following licenses that include the Enterprise DLP license
    Review the Supported Platforms for details on the required license for each enforcement point.
    • Prisma Access CASB license
    • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
    • Data Security license
  • Email DLP license
Enterprise Data Loss Prevention (E-DLP) monitors four operational metrics and sends an email notification to the recipients you specify when any enabled metric exceeds its configured threshold. Alerts are sent from dlp-noreply@paloaltonetworks.com; add this address to your organization's allow list to prevent alert notifications from being filtered as spam. Alerts have a 15-minute cooldown period — if a condition remains breached after the cooldown expires, Enterprise DLP sends another alert. You can independently enable or disable each alert type and configure all thresholds to match your environment's normal operating ranges.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationSaaS SecurityData SecuritySettingsEmail DLPAlert Settings.
  3. For each alert type you want to enable, enable the alert and enter a threshold value.
    • Failed Delivery Percentage—Whole-number percentage to trigger an alert when more than the specified percentage of messages fail delivery in a 10-minute window. Default is 5.
      Enterprise DLP monitors the percentage of emails that failed delivery (a non-delivery report was sent to the sender) in the last 10 minutes. A sustained high failure rate indicates downstream SMTP server unavailability or rejection. Lowering the threshold makes alerting more sensitive; raising it reduces noise for environments with higher baseline failure rates.
    • Deferred Queue Count—Maximum number of messages allowed in the deferred queue to trigger an alert when that number of messages or more are awaiting retry over a 15-minute window. Default is 1000.
      Enterprise DLP monitors the number of messages in the deferred delivery queue over the last 15 minutes. A growing deferred queue indicates that Enterprise DLP is retrying delivery to an unavailable or slow next-hop mail server. Lowering the threshold catches queue growth earlier; raising it reduces alerting for environments that tolerate higher deferred queue volumes.
    • Average DLP Scan Duration—Maximum acceptable average scan time in seconds to trigger an alert when the average inspection time exceeds that value over a 10-minute window. Default is 20.
      Enterprise DLP monitors the average inspection time per message in the last 10 minutes. Elevated average scan times indicate load or performance degradation in the Enterprise DLP service. Lowering the threshold provides earlier warning of service slowdowns; raising it reduces alerting in environments where higher baseline scan times are expected.
    • P95 DLP Scan Duration—Maximum acceptable 95th-percentile scan time in seconds to trigger an alert when the P95 inspection time exceeds that value over a 10-minute window. Default is 50.
      Enterprise DLP monitors the 95th-percentile inspection time per message in the last 10 minutes. P95 latency surfaces outlier scan delays that average metrics miss and is a leading indicator of service-level risk before average metrics are affected. Lowering the threshold catches tail latency spikes earlier; raising it reduces alerting for environments with wider scan-time distributions.
  4. In Notification Recipients, enter the email addresses or distribution list addresses that should receive alert notifications, then click Add after each address.
  5. Click Save.