cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
624
Views
0
Helpful
2
Replies

DLP

ziziahmed9
Level 1
Level 1

Hy,

pleaase I applied a dlp policy to my outgoing traffic , but I when I send an email that contain a attachment that should trigger dlp , there is no reaction . I see my log file even "dlp no violation" doen't appear . I think that it skips dlp engine 

Thanks 

2 Replies 2

quanganhkop01
Level 1
Level 1

Hello, Check DLP policy configuration: Review your DLP policy settings to ensure that it is correctly configured to detect and handle attachments. Verify that the file types and content patterns you expect to trigger the DLP policy are included in the policy rules. Verify DLP engine integration: Ensure that the DLP engine is properly integrated with your email system or security gateway. Confirm that the DLP engine is actively scanning outgoing emails and attachments. Check the configuration settings of your DLP solution and consult its documentation or support resources for specific troubleshooting steps. Test with different file types: Try sending emails with different types of attachments to see if the DLP policy triggers for certain file types but not others. This can help identify any specific issues with file type detection or policy rules. Monitor system logs: Examine system logs and event logs related to your DLP solution for any error messages or indications of issues that may be preventing the DLP policy from functioning correctly. Look for any log entries that may provide insights into why the DLP engine is not detecting violations. Seek vendor or IT support: If you have followed the above steps and are still unable to resolve the issue, consider reaching out to the vendor of your DLP solution or your IT support team for further assistance. They can provide specific guidance based on your setup and help diagnose and resolve any configuration or integration issues.  MyKFCExperience

I had a very similar issue. I created a DLP policy with a dictionary. The custom classifier had a each individual element had a weight of 1, i wanted 3 results so minimum score in the custom classifier was 3. 

It didn't trigger a violation. What I found was CISCO does some silly back-end logic to how they calculate scores. When i added zeros to the end of everything (weight 100, minimum score 300), etc... the DLP policies worked as expected.

So increase the weight of your rules and see how it goes.