You can see the detailed evidence information, such as its location, matched strings, and classifications criteria identified in the Evidence Details pane.
Category | Option | Definition |
|---|---|---|
General details | Type | Displays the type of the evidence format. |
Size | Displays the size of the evidence file. | |
Match count | Displays the total number of strings that have matched the rule. | |
Unique match count | Shows the unique number of strings that have matched the rule. | |
Short Match String | Shows the details of the matched string with the location of the evidence file and its SHA-1. | |
Other details | Unique Match Strings | Expand to display the matched strings. |
Classifications | Expand to display the classification criteria. |
Hyperlink to access evidence details of unmatched email attachments
Irrespective of the rule violation, you can access all evidences. Evidences of unmatched email attachments for the specified keywords or classifications are also hyperlinked and made downloadable. In the Protection Workspace → Protection Workspace → Incident details pane, click the evidence files of unmatched email attachments to download the evidence.
As a prerequisite, complete this task:
In Policy Catalog, navigate to Data Loss Prevention <version> → Server Configuration.
Create or edit the server configuration policy, and navigate to Shared Storage and Evidence → Incident Information.
Select Store all evidence to evidence share (used by DLP Network Prevent and DLP Network Monitor) and click Save.
All attachments available for download require additional storage space. Make sure that you have adequate storage for the expected download.