Data Collections
Data Collections are the data sources available in Insights.
You can select a data collection name to view the log record details in the Transaction Viewer page.
SSE
Available Data Collections for SSE:
- Admin:
This set of data applies to events where Forcepoint SSE suspects an unauthorized attempt to use an account. Example events include a series of failed login attempts on a specific user’s account, or a user attempting to login from diverse geographic locations within a short time window.
- CASBAPI:
This set of data applies to actions/activity taking place with data-at-rest via DLP scans (actions such as quarantine, or API policy matches).
- CASBInline:
This set of data includes suspicious activities involving sensitive data. For example, if a user sends an email containing matched keywords to a personal email account or if a file with sensitive data is accessed from several different locations in short succession.
- DLP:
This set of data applies to actions/activity taking place with data-at-rest via DLP scans (actions such as quarantine, or API policy matches) along with the information like Proxy Type and DLP Source IP.
- Health:
This set of data includes All Activities, Event Time, Application Name, HTTP request Method and others.
RBI
Available Data Collections for RBI:
- FileTransfer:
This set of data includes File name, File MIME, File URL, File Size, Processed Filesize, cdr performed, and AVscan performed details.
- Incidents:
This set of data includes Even Time, User information, Ads blocked, Scripts Isolated, and images sanitized details.
- SiteVisit:
This set of data includes Even Time, User information, Rendering Action, URL Categories, RBI Policy Rule Name,OS, Threat Score, and Browser Type details.