On
May 7, 2025,
Palo Alto Networks is introducing new
Evidence Storage and
Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
Prisma Browser
|
Or any of the following licenses that include the Enterprise DLP license
- Prisma Access CASB license
- Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license
- Data Security license
|
Enterprise Data Loss Prevention (E-DLP) uses clustering to detect sensitive data in structured
documents such as spreadsheets and CSV files. Clustering groups instances of sensitive
data that are close to each other and elevates a detection to High Confidence
when six or more detections of the same type appear in a row or column, even without
a proximity keyword in a header row. This enables Enterprise DLP to identify
sensitive data in structured documents that don't have header rows with column names
due to error or malicious intent.
However, if the underlying data pattern itself produces false positives, clustering
can amplify those inaccuracies across an entire column. Clustering can also produce
incorrect results when a single column contains values of multiple data types.
Configure the structured data settings to control clustering behavior for your Enterprise DLP tenant and reduce false positives in structured data
detection.