Use case: Tuning a rule to eliminate false positives

Prev Next

A rule called Block PCI information in the Protect financial data ruleset is identifying a large number of false positives.

Select the pre-defined Last 24 hours dataset for this example and specify the appliances that you want to run the search on.

  1. From the DLP Policy Manager, open the Protect financial data rule set and convert the Block PCI information rule into a capture search.

  2. Select the Last 24 hours dataset and save and run the search.

  3. Check the search results.

    Most of the results are for emails sent from the Finance department to either internal recipients, or trusted-partner.dom. These are legitimate emails that are triggering the false positives.

  4. Create an exception to Block PCI information rule that excludes messages sent from members of a Finance" LDAP group to recipients in the "Trusted recipients" email address list.

    Note

    Remember to enable the exception.

  5. Run the search again and review the results.

    The number of false positives is reduced.

  6. Save the search back to a rule, choosing to replace the original rule.