Edit the Enterprise DLP Snippet Settings
Focus
Focus
Enterprise DLP

Edit the Enterprise DLP Snippet Settings

Table of Contents
The Enterprise Data Loss Prevention (E-DLP) snippet settings allow you to configure if and how snippets of matched traffic are stored in the DLP cloud service.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
  • (Email DLP only) Data Security and Email DLP licenses
  • (Endpoint DLP only) Endpoint DLP license
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
A snippet is evidence or identifiable information associated with a data pattern match. You can configure if and how Enterprise Data Loss Prevention (E-DLP) stores and masks snippets of sensitive data that match your data pattern match criteria in an Enterprise DLP data profiles in the DLP cloud service. Your snippet setting configuration determines how snippets of matched traffic are displayed when you review your DLP Incidents.
Configure the Enterprise Data Loss Prevention (E-DLP) snippet settings on Strata Cloud Manager to specify if and how snippets are stored.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationData Loss PreventionSettingsSensitive Data.
  3. Enable Snippets Viewing and Masking for Prisma Access and NGFW to store the snippets of sensitive data that match your Enterprise DLP data patterns.
  4. Configure how to Snippets Masking for storage in the DLP cloud service.
    • Do not maskEnterprise DLP displays the entire matched sensitive data snippet in cleartext.
    • Partial maskEnterprise DLP partially masks the matched sensitive data snippet and displays only the last two characters in cleartext.
    • Full maskEnterprise DLP fully masks the entire matched sensitive data snippet.
  5. Push the snippet settings.
    1. Push Config and Push.
    2. Select (enable) Remote Networks and Mobile Users.
    3. Push.
Configure the Enterprise Data Loss Prevention (E-DLP) snippet settings on your Panorama™ management server to specify if and how snippets are stored.
  1. Log in to the Panorama web interface.
  2. Select PanoramaDLPConfiguration and edit the Snippet Settings.
  3. Check (enable) Store Snippets of Sensitive Data to store the snippets of sensitive data that match your data patterns in the DLP cloud service.
  4. Configure how to Mask Sensitive Field for storage in the DLP cloud service.
    • Do not maskEnterprise DLP displays the entire matched sensitive data snippet in cleartext.
    • Partial maskEnterprise DLP partially masks the matched sensitive data snippet and displays only the last two characters in cleartext.
    • Full maskEnterprise DLP fully masks the entire matched sensitive data snippet.
  5. Click OK to save your configuration changes.
  6. Commit and push the new configuration to your managed firewalls.
    The Commit and Push command isn’t recommended for Enterprise DLP configuration changes. Using the Commit and Push command requires the additional and unnecessary overheard of manually selecting the impacted templates and managed firewalls in the Push Scope Selection.
      Expand all
      Collapse all
    • Full configuration push from Panorama
    • Partial configuration push from Panorama
Configure the Email DLP snippet settings on Strata Cloud Manager to specify if and how snippets are stored.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationSaaS SecuritySettingsEmail DLP Settings.
  3. Configure the Snippet Viewing and Masking settings for Email DLP.
    • Do not maskEnterprise DLP displays the entire matched sensitive data snippet in cleartext.
    • Partial maskEnterprise DLP partially masks the matched sensitive data snippet and displays only the last two characters in cleartext.
    • Full maskEnterprise DLP fully masks the entire matched sensitive data snippet.
Configure the Endpoint DLP snippet settings on Strata Cloud Manager to specify if and how snippets are stored.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationData Loss PreventionSettingsSensitive Data.
  3. Enable Store Snippets of Sensitive Data for Endpoint DLP to store the snippets of sensitive data that match the data profile associated with your Endpoint DLP policy rule.
  4. Configure how to Snippets Masking for storage by Enterprise DLP.
    • Do not maskEnterprise DLP displays the entire matched sensitive data snippet in cleartext.
    • Partial maskEnterprise DLP partially masks the matched sensitive data snippet and displays only the last two characters in cleartext.
    • Full maskEnterprise DLP fully masks the entire matched sensitive data snippet.
  5. Push your new Endpoint DLP snippet settings to the Prisma Access Agent.
    1. Select Endpoint DLP PolicyPush Policies and Push Policies.
    2. (Optional) Enter a Description for the Endpoint DLP policy push.
    3. Review the Push Policies scope to understand the changes included the Endpoint DLP configuration push.
    4. Push.