Data Loss Prevention

 View Only
  • 1.  Rule Default Severity Overrides Severity Set By Match Count Range

    Posted Jun 18, 2015 09:33 AM

    I have a rule that I've got set up to set different severity levels based on match count.  1-10 is low, 10-100 is medium, 101+ is high.  I've uploaded the image from the console that shows this:

    dlp1.png

     

    Since this was set up, I've noticed that the severity will always be set to High for incidents matching this rule.  Let's say I'm looking at an incident with 1 match, I will go into the history and see the severity set twice after detection, first it will be set to low, then to high. 

    Under history, I'll see the events:

    1: Detected

    2: Severity Changed : Low

    3: Severity Changed : High

    When I go change the default level, entry 3 will be whatever I set the default severity to.  Is there a way to remove the default severity level? Or a way to make it so that it only sets the severity once?



  • 2.  RE: Rule Default Severity Overrides Severity Set By Match Count Range

    Trusted Advisor
    Posted Jun 19, 2015 02:46 AM

    Hello,

     I think the highest severity will be set by DLP between rules and default one.

    Set your default one to info, if you need to add some other rule to define it.

    If it does not work, let us know , Which DLP version are you using ?

     Regards



  • 3.  RE: Rule Default Severity Overrides Severity Set By Match Count Range

    Posted Jun 22, 2015 08:41 AM

    Using 12.5.2

    So you're saying set the default to info, and leave the rest?

    This will mark each incident as info, no matter the match count. For example, if there is an incident with a match count of 42, it will mark it as Medium first, then info.  The incident history will read : 

    1. Detected

    2. Severity Changed : Medium

    3. Severity Changed : Info



  • 4.  RE: Rule Default Severity Overrides Severity Set By Match Count Range

    Trusted Advisor
    Posted Jul 09, 2015 09:24 PM

    Poly..

    I think you have a misunderstabding of how the severity works.

    Default = is the initial value of the incident

    You then then added severities based on amount of matches.

    If you want severity of low = 1-9, medium = 10-100 high=101

    Here is what you do...

    Default = Low

    Medium = Greater than or equal to 10

    High = Greater than 101

     

    Good Luck

    Ronak

     

    Please marked as solved when possible



  • 5.  RE: Rule Default Severity Overrides Severity Set By Match Count Range

    Posted Sep 02, 2015 06:18 PM
    Interesting situation. I will check this in our terminal.