Provide the configuration to store the sensitive information on the external cloud storage such as Azure Storage or AWS S3 bucket to retrieve that content on a load while accessing the DLP IR Incident.

Before you begin

Role required: sn_dlir.admin(Create, edit, and delete)

sn_dlir.analyst - View (read-only)

Procedure

  1. On the progress bar, click the Match Content Configuration step.
  2. On the form, fill in the fields.
    Table 1. Match Content Configuration
    Field Description
    Store Match Content Option to store the matched content on the cloud storage.
    Important: If this option is not selected, the policy match content for DLP incidents cannot be seen in the DLP workspace. Enabling this option ensures that match content returned in the DLP incidents are stored in the external cloud storage (for example, Azure, AWS). You can also retrieve and display the match content whenever a DLP incident is opened in the workspace.

    For information on the External Cloud Storage configuration, see Install and configure the Microsoft DLP integration.

    Delete Match Content on Incident Deletion Option to delete the incident match content from the external cloud storage. This option is visible only when the Store Match Content field is selected.
    External Cloud Credentials The External Cloud Storage where the match content gets stored. You can refer to the External Cloud Credentials added for the Storage configuration. This option is visible only when the Store Match Content field is selected.
  3. Click Continue and move to the Scheduling section.