Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Properties tab
Administrator Help | Forcepoint DLP | Version 8.4.x
Define the threshold for matches and the fields to search for the classifier.
1.
Set the Threshold that determines the number of matches that trigger an incident:
*
Use At least to select the minimum number of matches that must be made (1-999).
*
Use Between to select an exact range of matches (1-999).
*
Use No match exists to trigger the rule if there are no matches.
2.
*
*
3.
Click Analyze Fields to view and select the fields to search for this classifier.
*
Select Search all available fields to search content fields that pose the highest risk of a policy breach. The fields are searched for the key phrases, regular expressions, dictionary terms, or fingerprints you specify. This is the default.
*
Select Search specific fields to identify one or more fields to search. The fields apply mainly to the email destination channel.
*
Search in All headers not covered in the above options. Includes all standard headers—Date, Message-ID, or Importance—as well as non-standard headers (x-headers, including x-mailer, x-spam-reason, and x-origin-ip) added during the sending of an email.
*
Search in User-defined header. Some organizations define x-headers to add custom information to the email message header. For example, they might create an x-header such as "X-MyCompany: Copyright 2017 MyCompany".

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2017 Forcepoint. All rights reserved.