Incident Statistics
Focus
Focus
Enterprise DLP

Incident Statistics

Table of Contents


Incident Statistics

View Email DLP alert threshold status and analyze incident trends by severity, action, and policy dimension using filterable charts and Top 5 rankings.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationSaaS SecurityData SecurityDashboard and choose Email DLP.
  3. Select Incident Statistics.
  4. Review the status of each alert threshold to confirm alerting is active and thresholds are set correctly for your environment.
    • Failed Delivery Percentage—Triggers when more than the configured percentage of messages fail delivery in a 10-minute window. A sustained high failure rate indicates that the next-hop mail server is unavailable or rejecting messages.
    • Deferred Queue Count—Triggers when the number of messages awaiting retry reaches or exceeds the configured count over a 15-minute window. A growing deferred queue indicates that Enterprise DLP is retrying delivery to a slow or unavailable downstream server.
    • Average DLP Scan Duration—Triggers when the average inspection time per message exceeds the configured threshold in seconds over a 10-minute window. Elevated average scan times indicate load or performance degradation in the Enterprise DLP service.
    • P95 DLP Scan Duration—Triggers when the 95th-percentile inspection time per message exceeds the configured threshold in seconds over a 10-minute window. P95 latency surfaces outlier scan delays that average metrics miss and is a leading indicator of service-level risk.
  5. Use the filter dropdowns to scope the incidents analytics charts.
    • Time filter—Choose Past 24 Hours, Past 7 Days, Past 30 Days, or Past 90 Days to set the scope of the incidents charts and Top 5 widgets.
    • Severity—Choose All, Very Low, Low, Medium, High, or Critical to filter incidents by policy match severity.
    • Action—Choose All, Monitored, Blocked, Manager approval, Admin approval, Quarantined, or Encrypted to filter by the action Enterprise DLP applied to matched messages.
    • Insight—Choose Policy, DLP Data Profile, or Sender User to set the grouping dimension for the Top 5 widgets.
  6. Review the Incidents in the Past chart to see how incident volume trended over the selected time window.
    The line chart plots incident count over time, with separate lines for each severity level. Use this chart to identify spikes in policy matches and correlate them with changes in email traffic or policy configuration.
  7. Review the Email Volume chart to see how processed message volume trended over the selected time window.
    The line chart plots email count over time, with separate lines for each action value. Use this chart alongside the incidents chart to determine whether an incident spike reflects a policy sensitivity change or an actual increase in risky email traffic.
  8. Review the Top 5 most matched widget to identify which policy rules, data profiles, or sender users generated the most incidents.
    The widget displays a vertical bar chart ranked by incident count for the Insight view you select. Each Insight option changes what the x-axis represents and whether a drilldown table appears when you select a bar.
    • Email DLP Policy
      Use this view to identify which Email DLP policy rules are generating the most incidents and to confirm that high-match counts reflect expected enforcement rather than misconfigured policy rules.
    • DLP Data Profile
      Use this widget to trace high-incident data profiles back to the specific policies that reference them. Select a data profile bar to open a detailed summary about that specific data profile. The table title identifies the matched data profiles and lists the Email DLP policy rules that reference them. Click the Policy Name to view a specific Email DLP policy rule.
    • Sender User
      Use this view to identify users who are frequently sending sensitive content. Select a sender bar to open a detailed summary about that specific sender. The table title identifies the matched sender and lists the Email DLP policy rules that matched their messages. Click the Policy Name to view a specific Email DLP policy rule.
  9. (Optional) Configure the Email DLP Alert Settings.
    Enter threshold values that reflect your organization's normal operating ranges. Alerts have a 15-minute cooldown. If a condition remains breached after the cooldown expires, Enterprise DLP sends another notification. Alert notifications are sent from dlp-noreply@paloaltonetworks.com. Add this address to your organization's allow list to prevent notifications from being filtered as spam.