---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure advanced settings

# Configure advanced settings {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to
identify the end users. In addition, activate and customize the evidence files preview properties.

## Before you begin

Role required:

* sn_dlir.admin
* sn_dlir.analyst and sn_dlir.analyst_read
{#configure-advanced-settings-dlp__ul_i4v_zgh_h5b}

## About this task

Configure the advanced settings on the Data Loss Prevention Incident Response to customize the details to display for an incident or control the duration to identify a repeat offender.

## Procedure

1. Navigate to AllDLP AdministrationAdvanced Settings.
2. On the form, fill in the fields.  
   {#configure-advanced-settings-dlp__table_dzh_lm5_vsb__entry__2}

   | Field | Description |
   |-|-|
   | Should sensitive data which caused the violation be displayed on the incident | Option to choose whether you want to display the sensitive data that caused the violation on the DLP incident. By default, this option is enabled. |
   | Should sensitive data which caused the violation be displayed on the cloned incidents as well? | Option to choose whether you want to display the sensitive data that caused the violation on the DLP cloned incident as well. By default, this option is turned off. |
   | List of fields on the incident that are used to identify the end user | The list of fields on the incident of the Assignment Rule module that are used to identify the end user. You can also specify your own custom attributes to identify the end user. |
   | Maximum number of incidents in a digest email | The maximum number of incidents that can be sent in a digest email. By default, the value is 100. |
   | Repeat offense maximum duration (in days) | The maximum duration to identify a repeat offender. By default, the value is 90 days. |
   | Quick mode to send emails | Option to validate emails and identify issues. You can perform the validation by enabling the Yes option. By default, this option is enabled. |
   | This property is for setting the log verbosity of the application | The log verbosity level of the application, meaning the name of the type of information. You can also update the value to the following options: * error * warn * info * debug {#configure-advanced-settings-dlp__ul_ucl_sp5_vsb} By default, the value is info. |
   | Should downloading the violating file of the reported incident be allowed | Option to download the violating file of the reported incident. By default, this option is Yes. |
   | Exclude cloned and child incidents from reports | Option to exclude the cloned and child incidents from the reports. By default, this option is Yes. |
   | Day(s) to wait for deleting match content on cloud storage after incident gets closed | Option to choose the number of wait days to clean up the match content of those incidents that are inactive for a specific time duration. By default, the value is 90. If the DLP incident is inactive after 90 days, the match content is cleaned up from the cloud storage. |
   | Assign Incident to DLP Analyst group after last escalation level | Select this check box to assign the incident to the analyst after the last escalation level. |
   | Allow users to access incidents post escalation | Select this check box to enable the assigned users to access the incidents after the escalation. When you select this option, all the users that were added to the escalation chain list can access the incidents. |
   | List of fields on the "sys_user" table that are used to uniquely identify the user in DLP workspaces | Options to uniquely identify the user in the DLP workspaces. The options are email and user_name. |
   | Allow analyst to edit completed assessment | Select this check box to enable the analyst to edit the completed assessment. When you select this option, the analysts can edit the Assessments, when unselected you can view the assessments in the Read-Only mode. |
   | List of valid file extensions. This property is a comma separated string. Each token indicates an extension. | List of the valid file extensions. Keep the field empty to allow all file extensions. |
   | Enabling this system property will display the Playbook tab under DLP Incidents and provide the option to manually trigger a playbook via the Add Playbook action | Option to display the Playbook tab and manually add the Playbook action. By default, this option is Yes. |
   | Evidence Files Preview Properties ||
   | Enabling this system property activates the evidence file preview feature in the DLP analyst workspace. sn_dlir.enable_evidence_file_preview | Option to choose whether you want to preview the evidence files directly in the workspace. By default, this option is Yes. |
   | This will allow DLP users to download the previewed evidence files. Once this property is enabled, users will see a download button in the document viewer to download the evidence file. sn_dlir.enable_download in_preview | Option to display the download button in the document viewer. The download button enables you to download the previewed evidence files. By default, this option is Yes. |
   | This property determines the duration for which files will be temporarily retained for evidence file preview purposes. (in minutes) sn_dlir.preview_temp_files_cleanup_interval | The maximum duration for which files are temporarily stored for evidence file preview. By default, the value is 10. If the DLP incident is inactive after 10 minutes, the evidence file is cleaned up from the analyst workspace. |
   | Enabling this property will extend the cleanup interval if evidence files are in use. This will allow the system to extend the expiry time of evidence files based on the value set in the system property "sn_dlir.preview_temp_files_cleanup_interval". sn_dlir.extend_cleanup_interval_on_usage | Option to extend the time before evidence files are deleted if they're being used. By default, this option is Yes. |
   | The maximum duration to extend the cleanup interval of evidence files (in minutes). sn_dlir.max_extension_duration_for_cleanup | Option to select how long, in minutes, the system keeps your evidence files before cleaning them up. By default, the value is 60. |
   [Table 1. Advanced Settings form]

   {#configure-advanced-settings-dlp__table_dzh_lm5_vsb}
3. Select Save.
**Related concepts**   

* [Monitor DLP Integration Run process](https://www.servicenow.com/docs/SEN6LY_8hKz6MD8ldIGuVA "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://www.servicenow.com/docs/9vlLhpUoXVMLbIOXaQG7AA "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://www.servicenow.com/docs/byIuJ~f0un4uAmDtYahOVg "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://www.servicenow.com/docs/3~7V6tLXfDyGR9elDsMk1g "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://www.servicenow.com/docs/4Nvihko2uI_cFDRh9j~dmA "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://www.servicenow.com/docs/xDBI2oXVU7y3svnRnEIPdQ "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://www.servicenow.com/docs/aGfuTB1~6JSqftIesOB6nQ "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://www.servicenow.com/docs/LZuUVX4lLn79vagW0wH76w "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://www.servicenow.com/docs/vVup03~8CFn_Aa~7NQVtsA "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://www.servicenow.com/docs/bQ7LBfNMV59D18ohgqIwSA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://www.servicenow.com/docs/4wU9FTaZr9_1sv5243aREA "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://www.servicenow.com/docs/cvKsTbRENDm2pzvMYTabuw "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://www.servicenow.com/docs/lUPlbqXTYbUc77Gzj_5H6w "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://www.servicenow.com/docs/bMy63OZMfsT~evTa~gr96w "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://www.servicenow.com/docs/Xn~YZ7ubcst6Qp3hGi3gZA "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://www.servicenow.com/docs/RA_omQ4xLGPRZmVdlTKDNQ "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://www.servicenow.com/docs/K_Vasn65TCCHVPJcNBeOfg "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://www.servicenow.com/docs/74i8xF9eMAJi_vMs7dMX5Q "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://www.servicenow.com/docs/VqR5XYIMrGZ2_YWVpnDHug "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [DLP Incidents Archival](https://www.servicenow.com/docs/uvETPiXeLxWT6j7T3DlXmg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://www.servicenow.com/docs/vo6L6EU_uyk1GYSEqwadBw "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


