|
Aggregates DLP incidents across all 6 enforcement channels (Endpoint
DLP, NGFW, Email DLP, Prisma® Access, SaaS API, and Prisma® Browser)
to detect users with a high volume of data loss prevention
violations. When a user exceeds the configured threshold (default: 5
medium/high/critical violations per day), Behavior Threats creates
an incident with drill-down details and links to UIM.
The policy ingests DLP violations from: Endpoint DLP, NGFW, Email
DLP, Prisma Access, SaaS API, and Prisma Browser. You can configure
the threshold, channels monitored, severity filter, enforcement
action filter, and data profiles to exclude.
|