Step11: View Forcepoint DLP incidents on the FSM

Viewing and managing reports for the DLP Cloud Applications feature is the same as for the on-premises DLP.

The main change involves what is displayed for a DLP incident:

  • Source- For Forcepoint DLP Cloud API channel the source value will be provided only for Google Workspace.
  • Action (expected)
  • Channel Name (operation done by end user e.g. File uploading/downloading)- Channel name can be DLP Cloud API or DLP Cloud Proxy
  • Destination-
    • Cloud application name
    • Cloud application type
  • Analyzed by: Data Protection Service
  • Detected by: Forcepoint Data Security Cloud | SSE CASB API OR Forcepoint Data Security Cloud | SSE CASB Proxy
Note: If the Destination > Cloud application type property displays Office 365- unknown application, it means that the Office 365 application type was not recognized by the Forcepoint Data Security Cloud | SSE CASB. In this case, the enforcement is done according to the selected option Office 365 > Other in the policy management.