Evidence Details pane

Prev Next

You can see the detailed evidence information, such as its location, matched strings, and classifications criteria identified in the Evidence Details pane.

Evidence details options

Category

Option

Definition

General details

Type

Displays the type of the evidence format.

Size

Displays the size of the evidence file.

Match count

Displays the total number of strings that have matched the rule.

Unique match count

Shows the unique number of strings that have matched the rule.

Short Match String

Shows the details of the matched string with the location of the evidence file and its SHA-1.

Other details

Unique Match Strings

Expand to display the matched strings.

Classifications

Expand to display the classification criteria.



Irrespective of the rule violation, you can access all evidences. Evidences of unmatched email attachments for the specified keywords or classifications are also hyperlinked and made downloadable. In the Protection WorkspaceProtection WorkspaceIncident details pane, click the evidence files of unmatched email attachments to download the evidence.

As a prerequisite, complete this task:

  1. In Policy Catalog, navigate to Data Loss Prevention <version>Server Configuration.

  2. Create or edit the server configuration policy, and navigate to Shared Storage and EvidenceIncident Information.

  3. Select Store all evidence to evidence share (used by DLP Network Prevent and DLP Network Monitor) and click Save.

All attachments available for download require additional storage space. Make sure that you have adequate storage for the expected download.