to
define which incidents the case management automation rule applies to.
You apply filters to narrow down and define the Enterprise DLP incident
scope. Enterprise DLP displays a preview of the recent Enterprise DLP incidents that match the rule to enable you to verify
you configured the rule scope correctly. The case management automation rule
retroactively applies only to future Enterprise DLP incidents.
Click Add Filter to apply any combination of the
following filters. Enterprise DLP supports selecting multiple filter
options from each type of filter.
- Action—Action taken by Enterprise DLP;
Alert, Block, and
Quarantine.
Severities—Severity of the Enterprise DLP incident;
Critical, High,
Medium, Low, and
Lowest.
Channels—Enforcement channel where the Enterprise DLP
incident occurred; Email DLP,
Endpoint DLP, NGFW, Prisma Access, Prisma Browser,
and SaaS API (Data Security)
Data Profile—All predefined and custom
custom
Enterprise DLP profiles.
Data Pattern—All predefined and
custom
Enterprise DLP data patterns.
Regions—Region where the Enterprise DLP incident
occurred.
In addition to the custom filters, you can specify a Data
Asset or URL Domain that against
which Enterprise DLP incidents are generated. You can enter a specific
Data Asset or URL Domain
in addition to custom filters, or not apply any customer filters and specify
only a Data Asset or URL
Domain. Enterprise DLP supports only one
Data Asset or one URL
Domain.
Enterprise DLP requires you add at least one filter, Data
Asset, or URL Domain to create the
case management automation rule.
Click Next to continue.