Step11: View Forcepoint DLP incidents on the FSM
Viewing and managing reports for the DLP Cloud Applications feature is the same as for the on-premises DLP.
The main change involves what is displayed for a DLP incident:
- Source- For Forcepoint DLP Cloud API channel the source value will be provided only for Google Workspace.
- Action (expected)
- Channel Name (operation done by end user e.g. File uploading/downloading)- Channel name can be DLP Cloud API or DLP Cloud Proxy
- Destination-
- Cloud application name
- Cloud application type
- Analyzed by: Data Protection Service
- Detected by: Forcepoint Data Security Cloud | SSE CASB API OR Forcepoint Data Security Cloud | SSE CASB Proxy
Note: If the property displays Office 365- unknown application, it means that the Office 365 application type was not recognized by the Forcepoint Data Security Cloud | SSE CASB. In this case, the enforcement is done according to the selected option in the policy management.
(1).jpg)