Hello,
We are in the process of rolling out DLP for the organisation.
It is important for us that we are able to detect outbound content which includes a certain number of unique e-mail addresses (or more). In such a case, the outbound communication should be stopped. We understand we can create logical rules which are designed to detect the number of occurrences of e-mail addresses within the content (files or mails), but it appears that in the case that an outbound e-mail body contains several occurrences of the same e-mail address (as would be the case of a mail conversation which has built up with many replies) then the rule is triggered and the outbound mail is stopped. Is there a way to ignore multiple occurrences of identical e-mail addresses and match instead against the total number of unique mail addresses?
I checked the forum and found this article which appears to be addressing the same issue but I couldn't see a resolution:
http://www.symantec.com/connect/forums/unique-match-count-email-addresses#comment-8624021
Thanks in advance