About Custom Document Types
Learn about how Enterprise Data Loss Prevention (E-DLP) uses custom documents you upload to prevent
exfiltration of sensitive data.
On
May 7, 2025,
Palo Alto Networks is introducing new
Evidence Storage and
Syslog Forwarding service IP
addresses to improve performance and expand availability for these services
globally.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
Prisma Browser
|
Or any of the following licenses that include the Enterprise DLP license
- Prisma Access CASB license
- Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license
- Data Security license
|
Enterprise Data Loss Prevention (E-DLP) supports upload and detection of custom documents containing
intellectual property for which you want to prevent exfiltration. You can upload a
custom document type to
Enterprise DLP, or use a
predefined document type, to classify and
detect standardized documents and prevent exfiltration of sensitive data. You use the
uploaded custom document types in
data profiles as match criteria.
Additionally, you can use custom document types along with
predefined machine learning-based data
patterns to apply additional ML-based detection algorithms complemented by
confidential or sensitive data specific to your organization.
Enterprise DLP
supports file and non-file inspection for both predefined and custom document types.
All custom documents you upload are isolated to the
Enterprise DLP tenant you upload
them to, and are not shared across different
Enterprise DLP tenants. This means
that if you want to use the same custom document in multiple data profiles in a
multi-tenant environment, you must upload the
custom document to each of the
Enterprise DLP tenants.
Using IDM and Trainable Classifiers for detection of sensitive data enables Enterprise DLP to continuously improve its detection capabilities by indexing
unstructured text in your documents.
You can't delete a custom document type after you add it to a
data profile. You need to remove the custom document type from
the data profile before you can delete it from
Enterprise DLP.
For example, your organization both buys and sells software. You want to only detect
instances of sensitive customer data contained in invoices for software that you sell.
In this case, you can upload a copy of your organization's invoice as a custom document
type for fingerprinting.
However, custom document types are less effective if you want to detect receipts for
software your organization purchases, because there is too much variance in format
between the various software vendors your organization purchases from. Greater document
variance results in less accurate detection of matched traffic.
Indexed Document Matching (IDM)
Used to fingerprint documents and create a document type for documents commonly used
by your organization. Uploading multiple documents allows you to create a custom
document repository that you can use in a data profile.
When you upload a custom document using IDM, Enterprise DLP stores the file in a
secure bucket and extracts the text from the uploaded custom document to generate
the document fingerprint. The original file cannot be reconstructed from the
generated fingerprint.
Enterprise DLP retains data from custom document uploads as follows:
Original uploaded document—Retained for 24 hours after upload.
Extracted text—Retained for 7 days.
Fingerprint—Retained until you delete the custom document type.
IDM Examples
Examples of different types of custom documents where IDM can be
successfully applied are:
Standardized forms or documents specific to your business or
organization
Patent documents
Specific business agreements
Specific intellectual property documents
Examples of different types of custom documents where IDM is less
successful because they are too generic or not specific to your
organization:
Trainable Classifiers
A supervised machine learning model that analyzes document types for classifications.
As you upload more custom documents as types,
Enterprise DLP can continuously
train the ML model to accurately detect sensitive data matches to inspect for and
prevent exfiltration (Positive Training Documents) and those to ignore (Negative
Training Documents). Uploading a set of custom documents using Trainable Classifiers
creates a custom document
model.
Enterprise DLP supports up to 10
unique custom document models for a single
Next-Generation
CASB for Prisma Access and NGFW or
Next-Generation
CASB for Prisma Access and NGFW (CASB-X) tenant.
Trainable Classifiers uses two types of training documents within a single custom
document model:
Positive Training Documents—Custom documents containing sensitive data
that you want Enterprise DLP to inspect for and prevent
exfiltration.
Negative Training Documents—Custom documents that you don't want Enterprise DLP to inspect for. Enterprise DLP ignores sensitive
data in these document types. In the event there is overlap between
documents in the positive and negative training sets, Enterprise DLP
inspects for and prevents exfiltration of the overlapping sensitive
data.
Enterprise DLP inspects only the first 2,500 characters of a document when
scanning for Trainable Classifier matches. Ensure that the most sensitive or
distinctive content in your documents appears within the first 2,500 characters to
achieve the most accurate detection results.