Xcitium Enterprise
Xcitium Client Security for Windows 12.15
English
Data Loss Prevention
Event Logs
- Click 'Logs' in XCS Menu bar
- Select 'Data Loss Prevention Events' from the drop-down at upper left.
- The Data Loss Prevention feature scans Windows endpoints for files containing sensitive information like social security numbers, credit card numbers and monitor file transfers with external storage devices.
- The scans and the monitoring are based on the scan rules and monitoring rules applied by the Xcitium Enterprise profile active on a device.
- The rules can be configured only by admins at the Xcitium Enterprise console.
- Date & Time - When the event occurred.
- Target - The item affected by the rule.
- DLP Monitoring event - Shows the type of external storage device to which the data transfer attempt was made
- DLP Discovery event - Shows the file path of the identified file
- Rule Name - The DLP rule that found the target item. This could be a DLP discovery rule or a monitoring rule.
- Rule Type - Whether rule is a DLP discovery rule or a removable storage rule
- Action - How the file was handled in the DLP event. The possible values are:
- Status – Shows whether the rule executed successfully or not
- Details - The specifics of the data found.
- DLP monitoring rule – Shows the removable storage device affected by the rule.
- DLP Discovery rule - Has a ‘Show details’ link which opens the specifics of the event.