Review Email DLP Incidents
Table of Contents
Expand all | Collapse all
-
- Register and Activate Enterprise DLP on Prisma Access (Panorama Managed)
- Edit the Enterprise DLP Snippet Settings on the DLP App
- Enable Role Based Access to Enterprise DLP on Strata Cloud Manager
- Enable Optical Character Recognition on Strata Cloud Manager
- Enable Optical Character Recognition for Enterprise DLP
-
-
- Create a Data Profile on the DLP App
- Create a Data Profile with EDM Data Sets on the DLP App
- Create a Data Profile with Data Patterns and EDM Data Sets on the DLP App
- Create a Data Profile with Nested Data Profiles on the DLP App
- Create a Data Profile on Strata Cloud Manager
- Create a Data Profile with EDM Data Sets on Strata Cloud Manager
- Create a Data Profile with Data Patterns and EDM Data Sets on Strata Cloud Manager
- Create a Data Profile with Nested Data Profiles on Strata Cloud Manager
- Create a Data Filtering Profile on Panorama
- Create a Data Filtering Profile on Panorama for Non-File Detection
- Update a Data Profile on the DLP App
- Update a Data Profile on Strata Cloud Manager
- Update a Data Filtering Profile on Panorama
- Enable Existing Data Patterns and Filtering Profiles
-
- How Does Email DLP Work?
- Activate Email DLP
- Add an Enterprise DLP Email Policy
- Review Email DLP Incidents
-
- Monitor DLP Status with the DLP Health and Telemetry App
- View Enterprise DLP Log Details on the DLP App
- Manage Enterprise DLP Incidents on the DLP App
- View Enterprise DLP Audit Logs on the DLP App
- View Enterprise DLP Log Details on Strata Cloud Manager
- Manage Enterprise DLP Incidents on Strata Cloud Manager
- View Enterprise DLP Audit Logs on Strata Cloud Manager
- View Enterprise DLP Log Details on Panorama
Review Email DLP Incidents
Review your
Enterprise Data Loss Prevention (E-DLP)
Email DLP incidents for outbound
emails.Where Can I Use This? | What Do I Need? |
---|---|
|
|
Review your
Enterprise Data Loss Prevention (E-DLP)
Email DLP incidents to understand which outbound
emails were inspected, review which were blocked, quarantined, or sent for approval,
and to download files inspected by Enterprise DLP
.- Log intoStrata Cloud Manager.
- Select.ManageConfigurationSaaS SecurityData SecurityIncidentsEmail DLP Incidents
- Review your Email DLP incidents.
- Severity—Severity of the DLP incident specified in the Email DLP policy.
- Updated On—Date the Email DLP incident status or assignee was updated.
- Created On—Date the Email DLP incident occurred.
- Sender—Email of the sender who generated the Email DLP incident.
- Subject—Subject line for the email that generated the Email DLP incident.
- Policy—Email DLP policy that the email matched against.
- Action—Action taken byEnterprise DLPbased on the Email DLP policy the outbound email matched against.
- Assigned to—Incident assignee responsible to review and address the Email DLP incident.
- Status—Resolution status of the Email DLP incident.
- Click the Email DLP incidentSubjectto view theIncident Details.
- TheFromandTofields display the email sender and recipient for the email that generated the DLP incident.
- TheEmail contentfield allows you to download the email in.emlformat.To successfully download an email, you must have configured evidence storage before the outbound email was inspected byEnterprise DLP. Emails of existing Email DLP incidents cannot be downloaded if you configure evidence storage after the Email DLP incident occurred.
- TheMatching Data Patternsshows snippets of the sensitive dataEnterprise DLPdetected and the data pattern that it matched.
- TheMessage IDcan be used to create a message trace on Microsoft Exchange Online or a custom Email Log Search on Gmail.
- (Quarantine only) If an outbound email was quarantined, an email administrator must review and approve these emails before they can continue to their intended recipient.