1.
|
3.
|
For Cloud Channels, use the File sync and sharing drop-down list to select an action to take when a breach is discovered during file sync or sharing with a cloud service, such as OneDrive for Business or Box.
|
![]() |
Select Permit to allow files to be synchronized or shared.
|
![]() |
Select Delete file to permanently erase the file that users are trying to sync or share. When a file is deleted, it cannot be recovered.
|
4.
|
By default, all incidents are audited. Clear the Audit incident check box if you do not want to audit incidents.
|
![]() |
Select Include forensics to include information about the transaction that resulted in the incident, such as the contents of an email body: From:, To:, Cc: fields; attachments, URL category, hostname, file name, and more.
|
![]() |
Select Run remediation script to have the system run a script when an incident is discovered, then select the script to use from the drop-down list. See Remediation scripts for more information.
|
![]() |
Select Run endpoint remediation script to have the system run an endpoint remediation script when an incident is discovered, then select the script to use from the drop-down list.
|
![]() |
Select Send syslog message to notify an outside syslog server or ticketing system of the incident.
|
![]() |
Select Send email notifications to send an email message to a designated recipient when a policy is breached.
|
![]() |
Click New to create a custom message.
|
5.
|
If you subscribe to Forcepoint DLP Discovery, click the Discovery tab, then:
|
![]() |
To have the system run a remediation script when an incident is discovered, select Run remediation script, then select a script from the drop-down list. See Remediation scripts.
|
![]() |
To have the system run an endpoint remediation script when an incident is discovered, select Run endpoint remediation script, then select a script from the drop-down list.
|
6.
|
Click OK to save your changes.
|
![]() |
Permit or allow the HTTP, HTTPS, or FTP request to go through.
|
![]() |
Block or deny the request.
|
2.
|
Select Audit incident to have Forcepoint DLP to log incidents. When logging is enabled, email notifications are also available.
|
3.
|
Select Send email notifications to send an email message to a designated recipient when a policy is breached.
|
![]() |
Click New to create a custom message.
|
4.
|
Click OK to save your changes.
|
![]() |
Permit the message to go through.
|
![]() |
Block or deny the message or post.
|
![]() |
Quarantine the message.
|
![]() |
Drop attachments that are in breach of policy. Quarantines email messages that:
|
![]() |
Encrypt the message.
|
2.
|
Select Audit incident to have Forcepoint DLP to log incidents in the incident database. By default, audit is selected irrespective of the action.
|
3.
|
If you select Send email notifications:
|
![]() |
Click New to create a custom message.
|
4.
|
Click OK to save your changes.
|