Video Screencast Help

incident reports on emails

Created: 16 Jun 2013 • Updated: 20 Jul 2013 | 9 comments
This issue has been solved. See solution.

Hi

 

Why there is no way to summarize incident reports based on recipients?? In general, reporting in DLP sucks, is there any better way to extract information from DLP?

Operating Systems:

Comments 9 CommentsJump to latest comment

pete_4u2002's picture

can you please let the incident report you looking for?

what is the informatin you are looking for?

 

reza akhlaghy's picture

Hi Pete,

I created a policy to monitor all emails. I want to have a report containing list of all emails summerized by users. But I need to have recipents column. I hope I made myself clear.

stephane.fichet's picture

Hi reza,

 You cannot summerize by recipient in DLP (but you can do it by recipient domain). You can try to use "IT analytics" solution (not sure you will be able to do that) or do it on your own via a CSV export of all your incident and then a processing of this export via excel or any other tool.

 I used to do lot of scripting a part of DLP in order to perform some report as DLP by itself does not have a very efficient reporting capabilities even if information are available in the tool.

 Regards.

reza akhlaghy's picture

Hi Stephane,

Summerizing by domain is enough, but where is it? All I can see is:

dlp summarize.png

stephane.fichet's picture

Hi

 oups, summarizing by domain is available for network incident but not for endpoint. So you will have to use incident export to get this information as this information si available in CSV export (it has to be processed cause you will have all recipients in same field).

 Regards

kishorilal1986's picture

Hi Reza,

U can summarize by recipient as per below

Incident Tab->All Reports>Networks

see the attached snapshot and also u can do this using customising reports as below

 

DLP reports 1.jpg DLP reports 2.jpg
SOLUTION
reza akhlaghy's picture

Ok,

but this is a network report, the actual incidents are releated to endpoints (emails users sent with their smtp clients). Is there anyway (rather than exporting to CSV!) to get that report?

Meanwhile I'm trying toinstall/understand this analytics add-on...

kishorilal1986's picture

Hi Reza,

Endpoint will not give above domainwise reports and if u are looking for mail recipient domainwise then ultimately if mail sent throgh Endpoint to networks (smtp) can give u such reports. there is no meaning at endpoint for recipient untill it sent out so consider the network reports for domain wise recipient.

I hope you will agree with this.

jgt10's picture

Reza,

If you haven't, open a support case and make an Enhancement Request.  Yes, I know it isn't going to help you in the short run. But ya never know until you ask. :)

JGT

--
John G. Thompson
JOAT(MON)