Cisco Cisco Email Security Appliance C390 사용자 가이드

다운로드
페이지 418
Chapter 2      Using Email Security Monitor
Email Security Monitor Pages
2-42
Cisco IronPort AsyncOS 7.3 for Email Daily Management Guide
OL-23080-01
Figure 2-20
Internal User Search Results
The DLP Incidents Page
The DLP Incidents page shows information on the incidents of data loss 
prevention (DLP) policy violations occurring in outgoing mail. The IronPort 
appliance uses the DLP email policies enabled in the Outgoing Mail Policies table 
to detect sensitive data sent by your users. Every occurrence of an outgoing 
message violating a DLP policy is reported as an incident. 
Using the DLP Incidents report, you can answer these kinds of questions:
  •
What type of sensitive data is being sent by your users?
  •
How severe are these DLP incidents?
  •
How many of these messages are being delivered?
  •
How many of these messages are being dropped?
  •
Who is sending these messages?
The DLP Incidents page is comprised of two main sections: 
  •
the DLP incident trend graphs summarizing the top DLP incidents by severity 
(Low, Medium, High, Critical) and policy matches, and
  •
the DLP Incidents Details listing.
You can select a time range on which to report (hour, day, week, or month). As 
with all reports, you can export the data for the graphs or the details listing to CSV 
format via the Export link or PDF format by clicking the Printable (PDF) link.