: Download Files for Evidence Analysis on Cloud Management
Focus
Focus

Download Files for Evidence Analysis on Cloud Management

Table of Contents

Download Files for Evidence Analysis on Cloud Management

Download files that match your
Enterprise Data Loss Prevention (E-DLP)
data profiles for
Prisma Access (Cloud Management)
and SaaS Security on
Cloud Management
.
After you successfully connect your AWS storage bucket, Azure storage bucket, or SFTP server to Cloud Management to store files that match your
Enterprise Data Loss Prevention (E-DLP)
data profiles, you can download to your local device any files scanned by the DLP cloud service to allow for in-depth investigation.
Files scanned by the DLP cloud service while
Enterprise DLP
is disconnected from your cloud storage bucket aren’t stored in your cloud storage. This means that all impacted files aren’t available for download. However, all snippet data is preserved and can still be viewed on
Cloud Management
.
  1. Connect your AWS storage bucket, Azure storage bucket, or SFTP server to
    Enterprise DLP
    if not already connected.
    The files available to download are only files scanned by the DLP cloud service after you successfully connected
    Enterprise DLP
    to your cloud storage bucket.
  2. (
    AWS and Azure only
    ) Log in to the Amazon AWS console or Microsoft Azure portal and access the cloud storage you connected to
    Cloud Management
    . Select
    Reports
    and enter a Report ID to
    Search
    .
    The object Name is the Report ID.
  3. In the Cloud Management Console, select
    Activity
    Logs
    DLP Incidents
    and search for the Report ID.
  4. Review report summary and click the download button to download the file to your device.
    Whether the stored file is downloaded directly to your local device is dependent on the storage bucket you connected to
    Enterprise DLP
    .
    • AWS and Azure
      —The file associated with the particular Report ID is downloaded locally to your device.
    • SFTP Server
      Cloud Management
      displays the folder path of the location the file was uploaded to on your SFTP server. You must access your SFTP server to download the file to your local device.

Recommended For You