Creating user-defined attributes and response rules in DLP

Article:HOWTO82820  |  Created: 2012-12-02  |  Updated: 2013-07-17  |  Article URL http://www.symantec.com/docs/HOWTO82820
Article Type
How To



Creating user-defined attributes and response rules in DLP

To identify whether a particular incident is a credit card (CC) leak or a social security number (SSN) leak, you must create a response rule by the using the Symantec DLP Web portal and set the CC and SSN attributes to 1. Other than CC or SSN, you can create a custom attribute that can define the information type of the incident. By doing this you will be able to categorize the incident information and panels such as 'Data Loss Incidents by Information Type'.

To create user-defined attributes in DLP

  1. Log in to the Symantec DLP Enforce Server Web portal.

  2. Go to System > Incident Data > Attributes page.

  3. Click the Custom Attributes tab.

  4. Click Add to add a new user-defined attribute.

    Type the name as CC for the user-defined attribute and select an attribute group.

    Repeat the steps to add SSN or any other user-defined attribute.

  5. Click Save.

To create a response rule

  1. Log in to the Symantec DLP Enforce Server Web portal.

    Make sure to add the Symantec DLP Enforce Server Web portal to the Trusted Sites in IE. Refer IE online help for Security zones: adding or removing websites.

  2. Go to the Manage > Policies > Response Rules workspace.

  3. Click Add Respone Rule to create a response rule.

  4. Select Automated Response and click Next.

  5. Provide a name and description for the rule. From the Actions drop-down menu, select an action and click Add Action.

  6. Select the Attribute as CC, SSN, or <custom_attribute> and enter the Value as 1.

  7. Click Save to save the configuration.

See Managing Symantec Data Loss Prevention connection


Legacy ID



v77186417_v82334133


Article URL http://www.symantec.com/docs/HOWTO82820


Terms of use for this information are found in Legal Notices