Introducing the Data Insight lookup plug-in

The Data Insight lookup plug-in pulls data from a
Veritas Data Insight
Management Server. It then uses that data to populate custom attributes for a
Network Discover
incident at the time the incident is generated. The Data Insight lookup plug-in connects
Symantec Data Loss Prevention
with
Veritas Data Insight
to retrieve attribute values. Data Insight can be used to provide granular context to incidents, including up-to-date data owner information.
The
Data Insight
page in the Enforce Server administration console is now accessible to all
Network Discover
customers without a license file.
You must create custom attributes for each attribute you want populated from the
Veritas Data Insight
Management Server. You create only the custom attributes that you need. When an incident is created, the Enforce Server retrieves data regarding that incident. Some of that data is in the form of "attributes." Custom attributes capture and store supplemental data that is related to the incident, such as the name of a relevant manager or department. See Configuring custom attributes in Help.
To populate custom attributes with the incident-related data, the Enforce Server uses the Data Insight lookup plug-in to retrieve the additional data from the
Veritas Data Insight
Management Server. You can chain the Data Insight lookup plug-in with other plug-ins, such as the LDAP lookup plug-in, CSV lookup plug-in, or Script lookup plug-in. For example, you may want to do this to set the
Data Owner Email Address
field. If the new lookup returns null or empty values for any custom attribute fields, those empty values overwrite the existing values.
The values for the custom attributes are updated by clicking
Lookup
in the
Attribute
section of the
Incident Snapshot
screen. This action replaces the existing values that are stored in the custom attribute fields with the values returned by the new lookup. See About lookup plug-ins in Help.
The
Veritas Data Insight
lookup plug-in can retrieve the following information from the
Veritas Data Insight
Management Server:
  • Data user. The data user is the user who most frequently accessed the file.
  • Business owner as defined in the
    Veritas Data Insight
    product.
  • Custodian. The custodian is the user who is responsible for remediation of the file. (Support for custodian information is available with
    Veritas Data Insight
    version 4.0 or later.)
  • Custodian Folder. The URI of the file system or SharePoint folder to which the custodian is assigned. (Support for custodian folder information is available with
    Veritas Data Insight
    version 4.0 or later.)
  • Data user last access time. The last time the data user accessed the file.
  • Data user access count. The number of times the data user accessed the file.
  • Most active users.
  • Most active readers.
  • Most active writers.
  • Read and write counts for each of the most active users, readers, or writers.
  • Last modified by.
  • Last accessed time.
  • Number of read accesses across all users.
  • Number of write accesses across all users.
  • The first time that access history was collected for this incident.