View Enterprise DLP Audit Logs
Focus
Focus
Enterprise DLP

View Enterprise DLP Audit Logs

Table of Contents

View Enterprise DLP Audit Logs

Use
Enterprise Data Loss Prevention (E-DLP)
audit logs to understand the change history for your
Enterprise DLP
deployment.
Where Can I Use This?
What Do I Need?
  • NGFW (Managed by Panorama)
  • Prisma Access (Managed by Strata Cloud Manager)
  • SaaS Security
  • NGFW (Managed by Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP)
    license
  • NGFW (Managed by Panorama)
    —Support and
    Panorama
    device management licenses
  • Prisma Access (Managed by Strata Cloud Manager)
    Prisma Access
    license
  • SaaS Security
    SaaS Security
    license
  • NGFW (Managed by Strata Cloud Manager)
    —Support and
    AIOps for NGFW Premium
    licenses
Or any of the following licenses that include the
Enterprise DLP
license
  • Prisma Access
    CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X)
    license
  • Data Security
    license
Review your
Enterprise Data Loss Prevention (E-DLP)
audit logs for a comprehensive history of the changes that occurred across your
Enterprise DLP
security service.
Enterprise DLP
audit logs maintain a history of when data patterns and data profiles are created, updated, or deleted.

Strata Cloud Manager

Use
Enterprise Data Loss Prevention (E-DLP)
audit logs to understand the change history for your
Enterprise DLP
deployment.
  1. Log in to
    Strata Cloud Manager
    .
  2. Select
    Manage
    Configuration
    Data Loss Prevention
    Audit Log
    .
  3. (
    Optional
    ) Filter the audit logs as needed.
    • Enter an email in the search bar to filter the audit logs by user.
    • Add New Filter
      to filter the audit logs based on:
      • Time
        ­ Select a predefined time frame or specify a
        Custom
        time frame.
      • Channel
        ­ Select a supported platform.
      • Event
        ­ Select the type of audit log event (
        Create
        ,
        Update
        , or
        Delete
        ) to view.
  4. Show More
    to view additional audit log information.
    You can view additional audit log details to review what traffic match criteria was configured when the data pattern, data filtering profile, or data profile was created or to better understand what changes were made.

DLP App

Use
Enterprise Data Loss Prevention (E-DLP)
audit Logs to understand the change history for your
Enterprise DLP
deployment.
  1. Log in to the DLP app on the hub.
    If you don’t already have access to the DLP app on the hub, see the hub Getting Started Guide. Only Superusers can access the hub.
  2. View the
    Audit Log
    .
  3. (
    Optional
    ) Filter the audit logs as needed.
    • Enter an email in the search bar to filter the audit logs by user.
    • Add New Filter
      to filter the audit logs based on:
      • Time
        ­ Select a predefined time frame or specify a
        Custom
        time frame.
      • Channel
        ­ Select a supported platform, including
        SaaS Security
        and
        Prisma Access
        , using Enterprise DLP.
      • Event
        ­ Select the type of audit log event (
        Create
        ,
        Update
        , or
        Delete
        ) to view.
  4. Show More
    to view additional audit log information.
    You can view additional audit log details to review what traffic match criteria was configured when the data pattern, data filtering profile, or data profile was created or to better understand what changes were made.

SaaS Security
(Email DLP Only)

View Email DLP audit logs on
SaaS Security
to understand the change history for your Email DLP configuration and deployment.
  1. Log in to
    Strata Cloud Manager
    .
  2. Select
    Manage
    Configuration
    SaaS Security
    Settings
    Monitor Actions Taken by SaaS Security
    .
  3. (
    Optional
    ) Filter the audit logs as needed.
    • Enter an email in the search bar to filter the audit logs by user.
    • Add Filter
      to filter the audit logs based on:
      • Role
        ­ Filter based on the admin role that made the configuration change.
      • Log
        ­ Filter based on the configuration change e
        Event
        type.
        The common Email DLP events are
        Create
        ,
        Update
        ,
        Delete
        , and
        Download
        .
      • Date
        ­ Select a predefined time frame or specify a
        Custom
        time frame.

Recommended For You