Data Collections

Data Collections are the data sources available in Insights.

You can select a data collection name to view the log record details in the Transaction Viewer page.

SSE

Available Data Collections for SSE:

  • Admin:

    This set of data applies to events where Forcepoint SSE suspects an unauthorized attempt to use an account. Example events include a series of failed login attempts on a specific user’s account, or a user attempting to login from diverse geographic locations within a short time window.

  • CASBAPI:

    This set of data applies to actions/activity taking place with data-at-rest via DLP scans (actions such as quarantine, or API policy matches).

  • CASBInline:

    This set of data includes suspicious activities involving sensitive data. For example, if a user sends an email containing matched keywords to a personal email account or if a file with sensitive data is accessed from several different locations in short succession.

  • DLP:

    This set of data applies to actions/activity taking place with data-at-rest via DLP scans (actions such as quarantine, or API policy matches) along with the information like Proxy Type and DLP Source IP.

  • Health:

    This set of data includes All Activities, Event Time, Application Name, HTTP request Method and others.

RBI

Available Data Collections for RBI:

  • FileTransfer:

    This set of data includes File name, File MIME, File URL, File Size, Processed Filesize, cdr performed, and AVscan performed details.

  • Incidents:

    This set of data includes Even Time, User information, Ads blocked, Scripts Isolated, and images sanitized details.

  • SiteVisit:

    This set of data includes Even Time, User information, Rendering Action, URL Categories, RBI Policy Rule Name,OS, Threat Score, and Browser Type details.