Enterprise DLP
Create a Classic Data Profile
Table of Contents
Expand All
|
Collapse All
Enterprise DLP Docs
Create a Classic Data Profile
Create a classic Enterprise Data Loss Prevention (E-DLP) data profile that contains predefined,
custom regular expression, or file property data patterns.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
You must allow these new service IP addresses on your network
to avoid disruptions for these services. Review the Enterprise DLP
Release Notes for more
information.
| Where Can I Use This? | What Do I Need? |
|---|---|
|
Or any of the following licenses that include the Enterprise DLP license
|
After you create a data pattern, you need to create a
data profile to add those data patterns and specify matches and confidence levels. A
classic data profile is a data profile that includes only regular expression (regex)
data patterns, or a data profile created on a Panorama® management server. Enterprise Data Loss Prevention (E-DLP) synchronizes all data profiles you create are shared across
Panorama, Strata Cloud Manager, and Prisma Browser deployments associated with the tenant. You can edit
all classic data profiles created on Panorama or Strata Cloud Manager as
needed.
(Panorama) A data profile for non-file traffic uses URL and
application exclusion lists. These lists let data security administrators exclude
specific traffic from inspection, with a predefined DLP App Exclusion
Filter available for common apps. When you create a data filtering
profile using predefined data patterns, be sure to consider the detection type used by the predefined data
patterns because the detection type determines how Enterprise DLP arrives at a
verdict for scanned traffic. Downgrading from PAN-OS 10.2.1 to 10.1
automatically converts non-file data filtering profiles to file-based data filtering
profiles.
(Prisma Browser) A classic data profile on Strata Cloud Manager is a data profile available to Prisma Browser users
without an active Enterprise DLP license that support predefined and custom
regex data patterns. In this case, you must create a classic data profile for
Local Detection.
When you create a data profile using predefined data patterns, be sure to consider
the detection type used by the predefined data
patterns because the detection type determines how Enterprise Data Loss Prevention (E-DLP) arrives
at a verdict for scanned files.
Updating a classic data profile to include an advanced detection method such as
Exact Data Matching (EDM) and custom document types set isn’t
supported.
You need to create an advanced data profile if you
want to create a data profile that combines a predefined or custom data pattern
and advanced detection methods, see