Use a Forensic Investigation search to look for content that was not previously identified as a potential data loss event.
In ePO - On-prem, select Menu → DLP Capture.
Select Actions → New Forensic Investigation.
Add a name and optional description for the new search.
Select an existing dataset or create a new one, and click OK.
The dataset shows an approximate number of captured items that will be evaluated with this dataset. If you are searching multiple appliances, the number shown is taken from the appliance that has the most events to evaluate.
If the number of events is too big to search in a reasonable amount of time, or too small to give a useful result, you can edit the dataset now.
The data refreshes the evaluation automatically.
In Max Results to Report, specify the number of results that you want to be available from the Search Results list.
(Optional) Select stop search when max results reached to prevent the search from analyzing more events than the number specified in Max Results to Report.
(Optional) Deselect Results: Store original files as evidence to improve performance and reduce the amount of data stored.
Add the conditions that you want the search to look for.
Click Save or Save & Run.