Data Loss Prevention

 View Only
  • 1.  Number of emails quarantined per work-day VS the ones allowed thru due to whitelists

    Posted Apr 27, 2017 12:52 PM

    I am trying get the average number of emails quarantined per work-day and the ones that are allowed through due to whitelists(such as authorized senders or safe listed addresses) Neen some ideas on how to setup the search/filter.

    Any help I can get would be appreciated. 

    Thank you.



  • 2.  RE: Number of emails quarantined per work-day VS the ones allowed thru due to whitelists

    Posted Apr 27, 2017 03:11 PM

    Remember we've have had a discussion in the past, pertaining to this topic:

    https://www.symantec.com/connect/forums/how-lookup-quarantined-emails

    If you already have separate statuses marking incidents that are quarantined (as in the thread above) - then all you need to do it to fetch daily, weekly, montly 'reports' for that status (example: "Quarantined") to find out the number of emails that were qurantined in day/daily average/etc.

    For email skipped due to whitelisting - I'd say its almost close to impossible to monitor/keep a count of those in an 'as is' state - unless you create a new policy which logs all the addresses, domains, etc. that are whiltelisted. That way you would be able to gather metrics on the the whitelisted adddresses, domains, etc.

    Hope this helps!