The Search List and Search Results

Prev Next

The DLP Capture feature displays information about each configured search in the Search List. From this page, you can create new searches and edit existing search settings. You can also select a search to see its results and export them. From the search results, you can select an individual result and see details about it.

The Search List

You can run up to five searches at the same time. If you try to run more than five searches concurrently, the later searches are queued until the required number of earlier searches finish.

Each search has a status, such as In progress, Canceled, Starting, or Finished. The Starting status displays until the Run action is received by one of the appliances in the dataset, when the status changes to In progress. You can also see when the search started, how long it took (elapsed time), and the number of positive matches that triggered.

Each search entry in the list shows the number of appliances that will be searched with this dataset and any search results. There are also some search-related actions: Delete, Duplicate, Run, or Cancel.

If you cancel a search while it is in progress, the number of results continues to increment for a short time until the appliance itself stops the search. You cannot edit a search that is in progress until all the appliances in the dataset have received the cancel command. A search cannot run if it references a single unavailable appliance.

Important

Deleting a search from the list removes the search results and all its related evidence items from the evidence folder. Similarly, if you run a search again, all the results and evidence items from the previous time it ran will be deleted. If you try to re-run a search that is in progress, the original results are removed and a new run of the same search begins.

You can export search results into two files. One contains a summary of the results and the other gives detailed information about each positive match.

If you export the results from the Search List, the two files contain results from each appliance that was searched as part of the dataset. If you want to export the results from the Appliance List, you can select one or more appliances to download results from.

There are some additional options available for each search within the list.

  • To view or edit a search settings, simply select the search name. If you make changes to the settings, you can save them to run later or run the search with the updated settings immediately.

  • To view information about results from appliances that are part of the specified dataset and see their health status, select the appliances link. From the Search Appliances List, you can see an appliance's current health status (not its health status at the time the search ran), and link to the Appliance Management feature to get more detailed status information. You can also export a summary of the results from one or more appliances.

  • For any search that produced results, you can select the number of results to get more information about those results.

Search Results

By default, the first 100 results from each appliance in a dataset are displayed in Search Results. For example, if the dataset includes five appliances, you can expect to see up to 500 results listed. However, you can specify a different number of results to display when you create the search.

Your selection of the Max Results to Report and stop search when max results reached options when you create a forensic investigation search or rule tuning search affect the results you see in the Search Results list.

For example, if you have one appliance in a dataset and the search criteria match against 150 items, the Max Results to Report option is set to 100, and the stop search when max results reached option is selected, the number of results in the Results tab, the Results column in the Search list, the Search Appliances list, and the results files are all 100. However, if stop search when max results reached is not selected, you see 100 results in the Results tab, but 150 results are reported in the results file, the Results column in the Search list, and the Search Appliances list.

Select a result to get more information about it, as well as any associated evidence and classifications that triggered. Each result has an individual identification number, and shows the reporting product and other information, such as the type of rule that triggered and any classifications.

If a captured item matches against any forensic investigation or rule tuning search, you can create an incident for that result that appears in the DLP Incident Manager. Details of the captured item are included in the incident in exactly the same way as if it had triggered a rule. You can also select one or more results to add to a new or existing case.

Search results details

Click a Result ID in Search Results to get detailed information about that individual result, including any classifications that triggered and associated evidence. You can deselect the option to collect evidence in the search settings to avoid storage and performance implications.

Note

A rule tuning result's details will tell you about any classifications that triggered, but will not include details of the rule that triggered.

The result can be added to an incident, exported into a report file, or added to a new or existing case. If you choose to create an incident from the result, a link to the incident is added to the result details.