: Review Email DLP Incidents
Focus
Focus

Review Email DLP Incidents

Table of Contents

Review Email DLP Incidents

Review your
Enterprise Data Loss Prevention (E-DLP)
Email DLP incidents for outbound emails.
Where Can I Use This?
What Do I Need?
  • Strata Cloud Manager
  • Enterprise Data Loss Prevention (E-DLP)
    license
  • Data Security
    license
  • Prisma Access
    license
  • AIOps for NGFW Premium
    license
  • AIOps for NGFW Free
    license
Review your
Enterprise Data Loss Prevention (E-DLP)
Email DLP incidents to understand which outbound emails were inspected, review which were blocked, quarantined, or sent for approval, and to download files inspected by
Enterprise DLP
.
  1. Log into
    Strata Cloud Manager
    .
  2. Select
    Manage
    Configuration
    SaaS Security
    Data Security
    Incidents
    Email DLP Incidents
    .
  3. Review your Email DLP incidents.
    • Severity
      —Severity of the DLP incident specified in the Email DLP policy.
    • Updated On
      —Date the Email DLP incident status or assignee was updated.
    • Created On
      —Date the Email DLP incident occurred.
    • Sender
      —Email of the sender who generated the Email DLP incident.
    • Subject
      —Subject line for the email that generated the Email DLP incident.
    • Policy
      Email DLP policy that the email matched against.
    • Action
      —Action taken by
      Enterprise DLP
      based on the Email DLP policy the outbound email matched against.
    • Assigned to
      —Incident assignee responsible to review and address the Email DLP incident.
    • Status
      —Resolution status of the Email DLP incident.
  4. Click the Email DLP incident
    Subject
    to view the
    Incident Details
    .
    • The
      From
      and
      To
      fields display the email sender and recipient for the email that generated the DLP incident.
    • The
      Email content
      field allows you to download the email in
      .eml
      format.
      To successfully download an email, you must have configured evidence storage before the outbound email was inspected by
      Enterprise DLP
      . Emails of existing Email DLP incidents cannot be downloaded if you configure evidence storage after the Email DLP incident occurred.
    • The
      Matching Data Patterns
      shows snippets of the sensitive data
      Enterprise DLP
      detected and the data pattern that it matched.
  5. (
    Quarantine only
    ) If an outbound email was quarantined, an email administrator must review and approve these emails before they can continue to their intended recipient.

Recommended For You