DLP Solutions2,
In the following post you add this information: https://www.symantec.com/connect/forums/dlp-and-ad-intergration
------------------------------------------------------------------------------------------------------------------------------------------
DIM: Data in motion
DAR: Data at Rest
DAE: Data at the Endpoint
I was referring to the LDAP Lookup Plugin, which will populate the custom attributes section in the incident snapshot. This is outlined in the Symantec_DLP_10.5_Lookup_Plugin_Guide. This requires modification to the following items:
Adding/Organinzing the Custom Attributes in the Enforce UI.
Plugin.properties file
LiveLdapLookup.properties
The AD authentication is the one that uses the krb5.ini file and requires a change in the Enforce UI under system Settings.
Which one do you need help with?
-------------------------------------------------------------------------------------------------------------------------------------------
I am tried to use the custom attribute as well without suceess.
The General screen of de Active directory show the follow information about the user:
First name: givenName
Last name:sn
Display name:displayName
Description:description
Office:physicalDeliveryOfficeName
Telephone number:telephoneNumber
E-mail:mail
In this case in System/Incident Data/Lookup Plugins I have to add a New LDAP plugin , and add in Attribute Mapping the next:
attr.First\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):givenName
attr.Last\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):sm
attr.Display\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):displayName
attr.Description=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):description
attr.Office=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):physicalDeliveryOfficeName
attr.Telephone\ number=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):telephoneNumber
attr.Email=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):mail
This step and configuration are correct?
The Plugin.properties file no has any configuration, I have to add this?
attr.First\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):givenName
attr.Last\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):sm
attr.Display\ name=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):displayName
attr.Description=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):description
attr.Office=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):physicalDeliveryOfficeName
attr.Telephone\ number=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):telephoneNumber
attr.Email=:(|(sAMAccountName=$endpoint-user-name$)(mail=$sender-email$)):mail
The LiveLdapLookup.properties not exist
And the "Adding/Organinzing the Custom Attributes in the Enforce UI"
The custom attribute to add are the follow?
First name
Last name
Display name
Description
Office
Telephone number
Email
Thank you very much for your assistance