Data Loss Prevention

 View Only
  • 1.  Sumantec DLP Network Discovery - v .15.0

    Posted Aug 12, 2021 06:38 PM
    Hi All,

    I have recently initiated a network discovery scan on one of the fileshare. While extracting the scan result output in csv , i need a customized output file which will have the parameter that includes the keyword or the regex which has been triggered against the defined rules i.e matches.
    I tried doing it using the advanced filters , but there is no such parameters in it where we can get the "matched keyword/regex" triggered against the rules.
    Any help/guidance would be appreciated.

    Thank you!


  • 2.  RE: Sumantec DLP Network Discovery - v .15.0

    Trusted Advisor
    Posted Sep 23, 2021 01:04 PM
    Anjali,

    There is no way to output the actual highlighted match (words or phrases is matched on) that the policy is looking for. This is a 'bad' way to pull out sensitive information from the system.

    The idea is that the Policy Name, counts or severity should give you the you the insight as to what was found and how much.

    There MIGHT be a way of doing this, but it will require a ton of SQL understanding and use of the API to pull it out. The actual event data is stored as an ENCRYPTED BLOB in the DB. It will require a ton of JAVA work and use of the API.. but it it will not be clean as EACH event will have a different output.

    So its not really readable.

    ------------------------------
    Good Luck. - RP
    PLEASE MARKED SOLVED WHEN POSSIBLE
    ------------------------------