View match details

Prev Next

You can view match strings (also known as snippets) and the name of the classification that identified them to find out more information about the rules that were triggered.

You must set up content classifications in ePO - SaaS to identify sensitive content.

  1. In ePO - SaaS Protection Workspace, click the incidents in Data Protection Overview to open the incident management workspace.

  2. In the Incidents pane, select the checkbox of the incident you want to view the match strings for.

  3. Expand Evidence in the Incident Details pane. This displays the evidence files associated with the incident.

  4. Click the file to open the Evidence Details pane. This displays the total match count, the 100-character short match string, a list of the unique match strings, and the classifications identified.

  5. Click the total match count to open the Match Details pane. This contains the snippets where keywords have matched.

    Note

    You can't click the total match count if you do not have permission to view the match details, or the match details file is not stored. To assign these permissions, in ePO - SaaS go to ConfigurationUsers & RolesAdd RoleAssigned PermissionsData ProtectionIncident Management and click the View and access match string files checkbox.

  6. Click the download icon next to the file name in the Incident Details pane to download the evidence.

This downloads the evidence file containing the match details.