Create a Data Profile
Focus
Focus
Enterprise DLP

Create a Data Profile

Table of Contents


Create a Data Profile

Create a data profile that can use regular expression (regex) data patterns and custom file property data patterns, and advanced detection methods.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Enterprise Data Loss Prevention (E-DLP) license
    Review the Supported Platforms for details on the required license for each enforcement point.
Or any of the following licenses that include the Enterprise DLP license
  • Prisma Access CASB license
  • Next-Generation CASB for Prisma Access and NGFW (CASB-X) license
  • Data Security license
After you create a data pattern, you need to create a data profile to add those data patterns and specify matches and confidence levels. A classic data profile is a data profile that includes only regular expression (regex) data patterns, or a data profile created on a Panorama® management server. Enterprise Data Loss Prevention (E-DLP) synchronizes all data profiles you create are shared across Panorama, Strata Cloud Manager, deployments associated with the tenant. You can edit all classic data profiles created on Panorama or Strata Cloud Manager as needed.
(Panorama) A data profile for non-file traffic uses URL and application exclusion lists. These lists let data security administrators exclude specific traffic from inspection, with a predefined DLP App Exclusion Filter available for common apps. When you create a data filtering profile using predefined data patterns, be sure to consider the detection type used by the predefined data patterns because the detection type determines how Enterprise DLP arrives at a verdict for scanned traffic. Downgrading from PAN-OS 10.2.1 to 10.1 automatically converts non-file data filtering profiles to file-based data filtering profiles.
When you create a data profile using predefined data patterns, be sure to consider the detection type used by the predefined data patterns because the detection type determines how Enterprise Data Loss Prevention (E-DLP) arrives at a verdict for scanned files.