Enable Exact Data Matching (EDM)
Focus
Focus
Enterprise DLP

Enable Exact Data Matching (EDM)

Table of Contents

Enable Exact Data Matching (EDM)

Enable Exact Data Matching (EDM) on Strata Cloud Manager and the DLP app on the hub.
On May 7, 2025, Palo Alto Networks is introducing new Evidence Storage and Syslog Forwarding service IP addresses to improve performance and expand availability for these services globally.
You must allow these new service IP addresses on your network to avoid disruptions for these services. Review the Enterprise DLP Release Notes for more information.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
Exact Data Matching (EDM) is an advanced detection tool to monitor and protect sensitive data from exfiltration. Use EDM to detect sensitive and personally identifiable information (PII) such as social security numbers, Medical Record Numbers, bank account numbers, and credit card numbers, in a structured data source such as databases, directory servers, or structured data files (CSV and TSV), with high accuracy. You must first enable EDM for Enterprise Data Loss Prevention (E-DLP) to upload hash encrypted EDM data sets to Enterprise DLP to use as match criteria in advanced data profiles.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationData Loss PreventionDetection MethodsExact Data Matching.
  3. Enable Exact Data Matching (EDM).
  4. Enterprise DLP automatically enables EDM on your tenant.
  5. Set up the EDM CLI app and upload EDM datasets to Enterprise DLP.
    1. Review the Supported EDM dataset formats to understand the data format types Enterprise DLP supports.
    2. Set up the EDM CLI app to begin uploading EDM datasets to Enterprise DLP.
    3. Configure the EDM CLI app connectivity to enable connectivity between the EDM CLI app and Enterprise DLP.