On
May 7, 2025,
Palo Alto Networks is introducing new
Evidence Storage and
Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
Prisma Browser
|
Or any of the following licenses that include the Enterprise DLP license
- Prisma Access CASB license
- Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license
- Data Security license
|
You can edit and modify an existing custom Enterprise Data Loss Prevention (E-DLP) data profile at
any time. Enterprise DLP synchronizes any changes you make to an existing data
profile between Panorama and Strata Cloud Manager.
If you update a data profile to include a predefined data pattern, be sure to
consider the
detection types used by the predefined
data patterns because the detection type determines how
Enterprise DLP arrives
at a verdict for scanned files. For example, when you create a data profile that
includes three machine learning (ML)-based data patterns and seven regex-based data
patterns,
Enterprise DLP will return verdicts based on the seven regex-based
patterns whenever the scanned file exceeds 1 MB.
Any changes to the data profile match criteria made on Strata Cloud Manager are
synchronized to Panorama but don’t display in the Panorama web
interface. Security policy rules using a data profile updated on Strata Cloud Manager inspect traffic using the new or modified match
criteria.
(Panorama only) Updating the data profile
Name is supported but you must manually update the
existing Security policy rules ( to reassociate the renamed data filtering profile. Commits on Panorama fail if you do not reassociate the renamed data filtering
profile with the Security policy rule after the updated data profile name is
synchronized to Panorama.
Update a Data Profile Strata Cloud Manager
Modify an existing Enterprise Data Loss Prevention (E-DLP) data profile on Strata Cloud Manager.
Log in to
Strata Cloud Manager.
Select and navigate to the data profile you want to modify.
Edit (
) the data profile.
Modify the data profile as needed.
For a nested data profile, the
DLP rule settings
apply to all data profiles added to the nested data profile
Enterprise DLP doesn't support converting an existing data profile into a nested data profile.
See
Create a Granular Data Profile for details configuring a single
data profile that contains multiple data profiles to enable you to
apply differentiated inline content inspection requirements and
response actions within the same Security policy rule.
You must
push the
Strata Cloud Manager configuration to the enforcement points using
the
Enterprise DLP when you create or
update a granular data
profile. For the Admin Scope, you must select
All
Admins to ensure all
Enterprise DLP configuration changes
propagate to impacted enforcement points.
When you add or update a granular data profile, the data profile
may temporarily stop enforcing until the push completes
successfully on all enforcement points. During this time,
traffic matching the profile's criteria can pass through
unchecked.
To minimize this enforcement gap, push your configuration changes
immediately after saving or schedule granular data profile
configuration pushes during a maintenance window.
Enterprise DLP configuration changes don't display in
Strata Cloud Manager
config snapshots.
Test a Data Profile
to verify it accurately detects the sensitive data you configured it to
detect.
Save your changes.
(
Nested and Granular Data Profiles) and
Push Config.
You must select
All Admins for the Admin Scope to
ensure all
Enterprise DLP configuration changes are
push to impacted enforcement
points. Learn more about when you need to
push configuration changes.
Enterprise DLP configuration changes don't display in
Strata Cloud Manager
config snapshots.
Update a granular data profile
You don't need a Strata Cloud Manager push if you made the following
changes:
Update the Match Scope for a nested or granular data profile.
When you update a granular data profile by adding or removing
child profiles, the profile may temporarily stop enforcing until
the push completes successfully on all enforcement points.
During this time, traffic matching the profile's criteria can
pass through unchecked. To minimize this enforcement gap, push
your configuration changes immediately after saving.
Update a Data Filtering Profile on Panorama
Modify an existing Enterprise Data Loss Prevention (E-DLP) data filtering profile on the Panorama® management server.
Log in to the
Panorama web
interface.
Select and
specify the
Device Group.
Select a data filtering profile to edit.
Modify the data filtering profile as needed.
See
Create a Data Profile for details on configuring configure a File or
Non-File data filtering profile that uses only predefined or custom
data patterns
For a data profile created on
Strata Cloud Manager that includes
advanced detection
methods,
Enterprise DLP only supports editing the data
filtering profile settings on
Panorama.
See
Create a Granular Data Profile on
Panorama for details
configuring a single data profile that contains multiple data
profiles to enable your data security administrators to apply
differentiated inline content inspection requirements and response
actions within the same Security policy rule.
Commit and push the new configuration to your
NGFW.
The Commit and Push command isn’t recommended for
Enterprise DLP configuration changes. Using the
Commit and Push command requires the
additional and unnecessary overheard of manually selecting the impacted
templates and managed firewalls in the Push Scope Selection.