Dimension Attributes
The following is a list of default cube dimensions and their associated attributes in the IT Analytics Symantec Data Loss Prevention Content Pack.
DLP Agent
Applicable cubes:
- DLP Agent Status
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
DLP Agent contains the following dimension attributes:
- Agent - AD User Name: User logged on to the endpoint computer at the time AD resolution is run
- Agent – Investigating: Denotes whether or not the agent’s status is set to Under Investigation
- Agent – IP Address: IP Address on the endpoint computer
- Agent – Is Deleted: Denotes whether or not the agent has been deleted from the endpoint server
- Agent – Name: Endpoint computer name
- Agent On or Off the Network: Indicates whether the agent is on or off the corporate network
- Agent – Status: Endpoint agent’s status
- Agent – Version: Endpoint agent’s full version number
- Agent – Major Version: Endpoint agent’s version number up to the third decimal place. This allows minor versions to be grouped more easily.
DLP Agent Last Connection Date
Applicable cubes:
- DLP Agent Status
DLP Agent Last Connection Date contains the following dimension attributes:
- Agent Last Connection Date – Date: Date the agent last connected to the endpoint server
- Agent Last Connection Date – Date Range: Date range the agent last connected to the endpoint server. Possible values are: Today, yesterday, 2 – 7 days ago, 8 – 14 days ago, and so on.
- Agent Last Connection Date – Day of Week: Day the agent last connected to the endpoint server
- Agent Last Connection Date – Month: Month the agent last connected to the endpoint server
- Agent Last Connection Date – Quarter: Quarter the agent last connected to the endpoint server
- Agent Last Connection Date – Week Number: Week number the agent last connected to the endpoint server
- Agent Last Connection Date – Year: Year the agent last connected to the endpoint server
DLP Agent Last Connection
Applicable cubes:
- DLP Agent Status
DLP Agent Last Connection contains the following dimension attributes:
- Agent Last Connection – Hour: Hour the agent last connected to the endpoint server
- Agent Last Connection – Minute: Minute the agent last connected to the endpoint server
- Agent Last Connection – Second: Second the agent last connected to the endpoint server
- Agent Last Connection – Time: Time the agent last connected to the endpoint server
DLP Captured Date
Applicable cubes:
- DLP Network Statistics
DLP Captured Date contains the following dimension attributes:
- Captured – Date: Date the message was captured by the detection server
- Captured – Date Range: Date range the message was captured by the detection server. Possible values are: Today, yesterday, 2 – 7 days ago, 8 – 14 days ago, and so on.
- Captured – Day of Week: Day the message was captured by the detection server
- Captured – Month: Month the message was captured by the detection server
- Captured – Quarter: Quarter the message was captured by the detection server
- Captured – Week Number: Week number the message was captured by the detection server
- Captured – Year: Year the message was captured by the detection server
DLP Captured Time
Applicable cubes:
- DLP Network Statistics
DLP Captured Time contains the following dimension attributes:
- Captured – Hour: Hour the message was captured by the detection server
- Captured – Minute: Minute the message was captured by the detection server
- Captured – Second: Second the message was captured by the detection server
- Captured – Time: Time the message was captured by the detection server
DLP Change Date
Applicable cubes:
- DLP Incident Status History
DLP Change Date contains the following dimension attributes:
- Change – Date: Date the incident status was changed
- Change – Date Range: Date range the incident status was changed. Possible values are: Today, yesterday, 2 – 7 days ago, 8 – 14 days ago, and so on.
- Change – Day of Week: Day the incident status was changed
- Change – Month: Month the incident status was changed
- Change – Quarter: Quarter the incident status was changed
- Change – Week Number: Week number the incident status was changed
- Change – Year: Year the incident status was changed
DLP Change Time
Applicable cubes:
- DLP Incident Status History
DLP Change Time contains the following dimension attributes:
- Change – Hour: Hour the incident status was changed
- Change – Minute: Minute the incident status was changed
- Change – Second: Second the incident status was changed
- Change – Time: Time the incident status was changed
DLP Change User
Applicable cubes:
- DLP Incident Status History
DLP Change User contains the following dimension attributes:
- Change – User: DLP user name that performed the change
DLP Condition
Applicable cubes:
- DLP Discover Incident Details
- DLP Endpoint Incident Details
- DLP Incident Details
- DLP Network Incident Details
- DLP Policy History
DLP Condition contains the following dimension attributes:
- Condition - Status: Captures historical changes of the condition status. Possible values are Created, Changed, Unchanged, and Deleted. The unchanged status will appear when a section/element of a compound condition is changed.
- Condition – Is Latest: Indicates whether or not this is the latest version of the condition
- Condition – Detection or Group: Indicates whether the condition belongs to one of two rule types
- Condition – ID: Condition ID
- Condition – Unique or Multiple Matches: Indicates the match counting type selected in the condition. Possible values are 1 – Check for existence, 2 – Count all matches, and 3 – Count all unique matches. A value of 1 will also be assigned if match counting is not applicable to the condition.
- Condition – Minimum Matches: Specifies the minimum number of matches required to trigger the condition and generate an incident
- Rule – Name: Name given to the detection or exception rule.
- Condition – Processing Order: Denotes the order in which conditions are processed
- Condition – Rule or Exception: Indicates whether the condition was added as a rule or as an exception
- Condition – Type: Describes the type of matching used in the condition. Possible values are Content Matches Data Identifier, Message Attachment or File Type Match, Content Matches Keyword, Sender/User Matches Pattern, and Protocol or Endpoint Destination.
DLP Condition Change Audit
Applicable cubes:
- DLP Policy History
DLP Condition Change Audit contains the following dimension attributes:
- Condition Change Audit – Attribute Name: Condition attribute name that was changed. Possible values are Data Source ID, Email Address, File Names, IP Address, Protocols, and so on.
- Condition Change Audit – Change Details: Details regarding the actual change in the condition
DLP Content Root Scan Started Date
Applicable cubes:
- DLP Discover Scans
DLP Content Root Scan Started Date contains the following dimension attributes:
- Content Root Scan Started – Date: Date the content root scan started
- Content Root Scan Started – Date Range: Date range the content root scan started
- Content Root Scan Started – Day of Week: Day the content root scan started
- Content Root Scan Started – Month: Month the content root scan started
- Content Root Scan Started – Quarter: Quarter the content root scan started
- Content Root Scan Started – Week Number: Week number the content root scan started
- Content Root Scan Started – Year: Year the content root scan started
DLP Content Root Scan Started Time
Applicable cubes:
- DLP Discover Scans
DLP Content Root Scan Started Time contains the following dimension attributes:
- Content Root Scan Started – Hour: Hour the content root scan started
- Content Root Scan Started – Minute: Minute the content root scan started
- Content Root Scan Started – Second: Second the content root scan started
- Content Root Scan Started – Time: Time the content root scan started
DLP Custom Attribute Name
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Custom Attribute Name contains the following dimension attributes:
- Custom Attribute – Name: Lists all user-defined custom attributes
DLP Custom Attribute Value
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Custom Attribute Value contains the following dimension attributes:
- Custom Attribute – Value: Lists values assigned to the custom attributes
DLP Data Owner
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Data Owner contains the following dimension attributes:
- Data Owner – Name: Name of the person responsible for remediating the incident. This field must be set manually, or with a lookup plug-in such as Data Insight.
DLP Data Owner Email
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Details
DLP Data Owner Email contains the following dimension attributes:
- Data Owner – Email: Email address of the person responsible for remediating the incident. This field must be set manually, or with a lookup plug-in such as Data Insight.
DLP Database Info Condition
Applicable cubes:
- DLP Policy History
DLP Database Info Condition contains the following dimension attributes:
- Database Info Condition – ClauseID: ID number in the condition WHERE clause. This is only applicable to policies which use Exact Data Matching (EDM)
- Database Info Condition – DataSourceID: EDM profile ID number
- Database Info Condition – Threshold: Number of selected fields to match on EDM profile
DLP Date Condition Created
Applicable cubes:
- DLP Policy History
DLP Date Condition Created contains the following dimension attributes:
- Condition Created – Date: Date the condition was created
- Condition Created – Date Range: Date range the condition was created
- Condition Created – Day of Week: Day the condition was created
- Condition Created – Month: Month the condition was created
- Condition Created – Quarter: Quarter the condition was created
- Condition Created – Week Number: Week number the condition was created
- Condition Created – Year: Year the condition was created
DLP Date Condition Edited
Applicable cubes:
- DLP Policy History
DLP Date Condition Edited contains the following dimension attributes:
- Condition Edited – Date: Date the condition was edited (shows historical data)
- Condition Edited – Day of Week: Day the condition was edited (shows historical data)
- Condition Edited – Date Range: Date range the condition was edited (shows historical data)
- Condition Edited – Month: Month the condition was edited (shows historical data)
- Condition Edited – Quarter: Quarter the condition was edited (shows historical data)
- Condition Edited – Week Number: Week number the policy was created (shows historical data)
- Condition Edited – Year: Year the condition was edited (shows historical data)
DLP Date Policy Created
Applicable cubes:
- DLP Policy History
DLP Date Policy Created contains the following dimension attributes:
- Policy Created – Date: Date the policy was created
- Policy Created – Date Range: Date range the policy was created
- Policy Created – Day of Week: Day the policy was created
- Policy Created – Month: Month the policy was created
- Policy Created – Quarter: Quarter the policy was created
- Policy Created – Week Number: Week number the policy was created
- Policy Created – Year: Year the policy was created
DLP Date Policy Edited
Applicable cubes:
- DLP Policy History
DLP Date Policy Edited contains the following dimension attributes:
- Policy Edited – Date: Date the policy was edited (shows historical data)
- Policy Edited – Day of Week: Day the policy was edited (shows historical data)
- Policy Edited – Month: Month the policy was edited (shows historical data)
- Policy Edited – Quarter: Quarter the policy was edited (shows historical data)
- Policy Edited – Year: Year the policy was edited (shows historical data)
DLP Detection Date
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Detection Date contains the following dimension attributes:
- Detection – Date: Incident detection date as reported by the detection server
- Detection – Date Range: Incident detection date range as reported by the detection server
- Detection – Day of Week: Incident detection day as reported by the detection server
- Detection – Month: Incident detection month as reported by the detection server
- Detection – Quarter: Incident detection quarter as reported by the detection server
- Detection – Week Number: Incident detection week number as reported by the detection server
- Detection – Year: Incident detection year as reported by the detection server. These values correspond to the Reported On timestamp in the Endpoint Incident Snapshot, which represents the date/time when the incident was processed by the endpoint server.
DLP Detection Server
Applicable cubes:
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
- DLP Network Statistics
DLP Detection Server contains the following dimension attributes:
- Detection Server – Name: Detection server name as shown in the Systems Overview page
- Detection Server – Type: Detection Server channel name as shown in the System Overview page
DLP Detection Time
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Detection Time contains the following dimension attributes:
- Detection – Time: Incident detection time as reported by the detection server
- Detection – Hour: Incident detection hour as reported by the detection server
- Detection – Minute: Incident detection minute as reported by the detection server
- Detection – Second: Incident detection second as reported by the detection server. These values map to the Reported On timestamp in the Oracle database, which represents when the incident was processed by the endpoint server.
DLP Discover Incident
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Discover Scans
DLP Discover Incident contains the following dimension attributes:
- Discover Incident – Content Root: Lists Content Roots that were scanned by the discover server. This list only contains content roots in which at least one sensitive file was found
- Discover Incident – Document Name: Name of the file that triggered the incident
- Discover Incident – File Owner: Creator of the file or item that triggered the incident
- Discover Incident – Repository Location: Full path of the file that triggered the incident
- Discover Incident – Scanned Machine: Host name of the scanned computer
- Discover Incident – Target Type: Discover target type. Possible values are File System, Lotus Notes, SQL Database, SharePoint, Exchange, File System Endpoint, Web Services, and Scanner (SharePoint, Exchange, Web Server, File System, Documentum, LiveLink, and Generic).
DLP Discover Incident File Location
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident File Location contains the following dimension attributes:
- Discover Incident – File Location: Full path of the file that triggered the incident
DLP Discover Incident File Permission ACL Type
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident File Permission ACL Type contains the following dimension attributes:
- Discover Incident – ACL Type: ACL permission type. Possible values are File and SP (SharePoint).
DLP Discover Incident File Permission Grant or Deny
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident File Permission Grant or Deny contains the following dimension attributes:
- Discover Incident – Grant or Deny: Indicates whether the ACL type assigned permission is grant or deny
DLP Discover Incident File Permission
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident File Permission contains the following dimension attributes:
- Discover Incident – File Permission: Permission assignment corresponding to the Grant or Deny dimension. Possible values are Read and write.
DLP Discover Incident File Permission Username
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident File Permission Username contains the following dimension attributes:
- Discover Incident – File Permission Username: User name or group granted the given file permission
DLP Discover Incident Protect Status
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
DLP Discover Incident Protect Status contains the following dimension attributes:
- Discover Incident – Protect Status: Indicates the remediation action taken on the discovered file. Possible values are Endpoint File Quarantine, Protect File Copied, No Remediation, and so on.
DLP Discover Scan
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Discover Scan
DLP Discover Scan contains the following dimension attributes:
- Discover Scan – In Process Scan: Indicates whether or not the scan is in progress
- Discover Scan – Initial Scan: Indicates whether or not this is the first scan performed on the discover target
- Discover Scan – Last Completed Scan: Indicates whether or not this is the last scan performed on the discover target
- Discover Scan – Scan Instance ID: Discover scan instance ID
- Discover Scan – Target Type: Denotes the type of data repository being scanned
DLP Discover Server
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Discover Scan
DLP Discover Server contains the following dimension attributes:
- Discover Server – Name: Discover server name
DLP Discover Scan Content Root
Applicable cubes:
- DLP Discover Scans
DLP Discover Scan Content Root contains the following dimension attributes:
- Discover Scan – Content Root: Lists all Content Roots scanned by the discover server. The list includes content roots that have not sensitive data.
DLP Discover Target
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Discover Scans
DLP Discover Target contains the following dimension attributes:
- Discover Target – Name: Discover target name as shown in the Enforce console
DLP Document Meta Info Condition
Applicable cubes:
- DLP Policy History
DLP Document Meta Info Condition contains the following dimension attributes:
- Document Meta Info Condition – MIMEType: Message attachment or file type MIME type
DLP Document Name Condition
Applicable cubes:
- DLP Policy History
DLP Document Name Condition contains the following dimension attributes:
- Document Name Condition – Filenames: Files names used in the Message Attachment or File Name Match condition
DLP Document Profile Condition
Applicable cubes:
- DLP Policy History
DLP Document Profile Condition contains the following dimension attributes:
- Document Profile Condition – DocSourceID: Indexed Document Matching (IDM) profile ID number
- Document Profile Condition – Similarity: Document Profile Condition – Similarity: IDM similarity threshold
DLP Document Size Condition
Applicable cubes:
- DLP Policy History
DLP Document Size Condition contains the following dimension attributes:
- Document Size Condition – Document Size: Document size specified within Message attachment or file size match condition type
- Document Size Condition – Size Comparator: Size comparator type specified within Message attachment or file size match condition type. Possible values are 1 for greater than and 2 for less than.
- Document Size Condition – Size Magnitude: Unit type used within Message Attachment or File Size Match condition type. Possible values are 0 for bytes, 1 for kilobytes, 2 for megabytes, and 3 for gigabytes.
DLP Endpoint Incident
Applicable cubes:
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Summary
DLP Endpoint Incident contains the following dimension attributes:
- Endpoint Incident – Application Name: The name of the application employed by the user
- Endpoint Incident – Device Type: Lists the endpoint monitoring channel that triggered the incident
- Endpoint Incident – File Name: Destination name of the file or item that triggered the incident
- Endpoint Incident – File Owner: Creator of the file or item that triggered the incident
- Endpoint Incident – File Path: Full destination path of the file that triggered the incident
- Endpoint Incident – Instance ID: Endpoint device identifier on which the violation occurred
- Endpoint Incident – IP Address: IP address of the endpoint at the time the violation occurred
- Endpoint Incident – Machine Name: Name of the computer that triggered the incident
- Endpoint Incident – On or Off the Network: Indicates the agent location at the time the violation occurred
- Endpoint Incident – Source File Name: Name of the file or item that triggered the incident
- Endpoint Incident – Source File Path: Full path of the file that triggered the incident
- Endpoint Incident – User Name: Logged on user on the computer that triggered the incident
DLP Endpoint Incident Agent Response
Applicable cubes:
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
DLP Endpoint Incident Agent Response contains the following dimension attributes:
- Endpoint Incident – Agent Response: Response or action taken by the endpoint agent
DLP Endpoint Incident User Justification
Applicable cubes:
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
DLP Endpoint Incident User Justification contains the following dimension attributes:
- Endpoint Incident – User Justification Response: Justification response as defined in the Enforce console
- Endpoint Incident – User Justification Type: Justification type as defined in the Enforce console. The possible default values are User Education, Broken Business Process, Manager Approved, and False Positive.
DLP Endpoint Server
Applicable cubes:
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
DLP Endpoint Server contains the following dimension attributes:
- Endpoint Server - Name: Endpoint server name
DLP File Created Date
Applicable cubes:
- DLP Discover Scans
DLP File Created Date contains the following dimension attributes:
- File Created – Date: Date the discovered file was created
- File Created – Date Range: Date range the discovered file was created
- File Created – Day of Week: Day the discovered file was created
- File Created – Month: Month the discovered file was created
- File Created – Quarter: Quarter the discovered file was created
- File Created – Week Number: Week number the discovered file was created
- File Created – Year: Year the discovered file was created
DLP File Created Time
Applicable cubes:
- DLP Discover Scans
DLP File Created Time contains the following dimension attributes:
- File Created – Hour: Hour the discovered file was created
- File Created – Minute: Minute the discovered file was created
- File Created – Second: Second the discovered file was created
- File Created – Time: Time the discovered file was created
DLP File Last Accessed Date
Applicable cubes:
- DLP Discover Scans
DLP File Last Accessed Date contains the following dimension attributes:
- File Last Accessed – Date: Date the discovered file was last accessed
- File Last Accessed – Date Range: Date range the discovered file was last accessed
- File Last Accessed – Day of Week: Day the discovered file was last accessed
- File Last Accessed – Month: Month the discovered file was last accessed
- File Last Accessed – Quarter: Quarter the discovered file was last accessed
- File Last Accessed – Week Number: Week number the discovered file was last accessed
- File Last Accessed – Year: Year the discovered file was last accessed
DLP File Last Accessed Time
Applicable cubes:
- DLP Discover Scans
DLP File Last Accessed Time contains the following dimension attributes:
- File Last Accessed – Hour: Hour the discovered file was last accessed
- File Last Accessed – Minute: Minute the discovered file was last accessed
- File Last Accessed – Second: Second the discovered file was last accessed
- File Last Accessed – Time: Time the discovered file was last accessed
DLP Incident
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident History
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Incident contains the following dimension attributes:
- Incident – ID: Incident ID
DLP Incident History Date
Applicable cubes:
- DLP Incident History
DLP Incident History Date contains the following dimension attributes:
- Incident History Date – Date: Date the event occurred
- Incident History Date – Date Range: Date range the event occurred
- Incident History Date – Day of Week: Day the event occurred
- Incident History Date – Month: Month the event occurred
- Incident History Date – Quarter: Quarter the event occurred
- Incident History Date – Week Number: Week number the event occurred
- Incident History Date – Year: Year the event occurred
DLP Incident History Detail
Applicable cubes:
- DLP Incident History
DLP Incident History Detail contains the following dimension attributes:
- Incident History – Detail: Free text description of the event
DLP Incident History Submitted By
Applicable cubes:
- DLP Incident History
DLP Incident History Submitted By contains the following dimension attributes:
- Incident History – Submitted By: DLP user name who performed the action
DLP Incident History Time
Applicable cubes:
- DLP Incident History
DLP Incident History Time contains the following dimension attributes:
- Incident History – Hour: Hour the event occurred
- Incident History – Minute: Minute the event occurred
- Incident History – Second: Second the event occurred
- Incident History – Time: Time the event occurred
DLP Incident History Type
Applicable cubes:
- DLP Incident History
DLP Incident History Type contains the following dimension attributes:
- Incident History – Type: Type of event as shown in the history tab of the incident snapshot. Possible values are Action Blocked, Attribute Lookup Completed, Attribute Set, Detected, Severity Change, Status Change, User Notified, and so on.
DLP Incident Message Component Document Format
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Incident Message Component Document Format contains the following dimension attributes:
- Message Component – Document Format: File format used in the message
DLP Incident Message Component Mime Type
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
- DLP Incident Message Component Mime Type contains the following dimension attributes:
- Message Component – MIME Type: MIME type used in the message
DLP Incident Message Component Name
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Incident Message Component Name contains the following dimension attributes:
- Message Component – Name: Name used in the message
DLP Incident Next Status
Applicable cubes:
- DLP Incident Status History
DLP Incident Next Status contains the following dimension attributes:
- Incident – Next Status: Next status assigned to the incident. If the incident status is not changed, next status will be set to unknown
DLP Incident Next Status Group
Applicable cubes:
- DLP Incident Status History
DLP Incident Next Status Group contains the following dimension attributes:
- Incident – Next Status Group: Next status group as defined in the Enforce console
DLP Incident Severity
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Discover Scans
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
- DLP Network Statistics
DLP Incident Severity contains the following dimension attributes:
- Incident – Severity: Incident severity. Possible values are Info, Low, Med, and High.
DLP Incident Status
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Incident Status contains the following dimension attributes:
- Incident – Status: Incident status as shown in the incident snapshot
DLP Incident Status Group
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Incident Status Group contains the following dimension attributes:
- Incident – Status Group: Incident status group as defined in the Enforce console
DLP Incident Type
Applicable cubes:
- DLP Incident Details
- DLP Incident Status History
- DLP Incident Summary
DLP Incident Type contains the following dimension attributes:
- Incident – Product Area: Incident type. Possible values are Network, Endpoint, and Data at rest.
DLP Keyword Condition
Applicable cubes:
- DLP Policy History
DLP Keyword Condition contains the following dimension attributes:
- Keyword Condition – Case Sensitive: Match type used within the Content Matches Keyword condition type. Possible values are Case Sensitive and Case Insensitive
- Keyword Condition – Delimiter: Keyword separator used within the Content Matches Keyword condition type. Possible values are Newline and comma.
- Keyword Condition – Is Tokenized Search: Indicates whether or not keyword searches are tokenized. The default value is yes.
- Keyword Condition – Keyword List: Keyword list specified within the Content Matches Keyword condition type
DLP Last State Changed Date
Applicable cubes:
- DLP Discover Scans
DLP Last State Changed Date contains the following dimension attributes:
- Last State Changed – Date: Date the scan status last changed
- Last State Changed – Date Range: Date range the scan status last changed
- Last State Changed – Day of Week: Day of the week the scan status last changed
- Last State Changed – Month: Month the scan status last changed
- Last State Changed – Quarter: Quarter the scan status last changed
- Last State Changed – Week Number: Week number the scan status last changed
- Last State Changed – Year: Year the scan status last changed
DLP Last State Changed Time
Applicable cubes:
- DLP Discover Scans
DLP Last State Changed Time contains the following dimension attributes:
- Last State Changed – Hour: Hour the scan status last changed
- Last State Changed – Minute: Minute the scan status last changed
- Last State Changed – Second: Second the scan status last changed
- Last State Changed – Time: Time the scan status last changed
DLP Message Date
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint incident Details
- DLP Endpoint Incident Summary
- D LP Incident Details
- DLP Incident Summary
- DLP Network Incident Summary
- DLP Network Incident Details
DLP Message Date contains the following dimension attributes:
- Message – Date: Date the message was received by the detection server or endpoint client
- Message – Date Range: Date range the message was received by the detection server or endpoint client
- Message – Day of Week: Day the message was received by the detection server or endpoint client
- Message – Month: Month the message was received by the detection server or endpoint client
- Message – Quarter: Quarter the message was received by the detection server or endpoint client
- Message – Week Number: Week number the message was received by the detection server or endpoint client
- Message – Year: Year the message was received by the detection server or endpoint client
- Message – Hour: Hour the message was received by the detection server or endpoint client
- Message – Minute: Minute the message was received by the detection server or endpoint client
- Message – Second: Second the message was received by the detection server or endpoint client
- Message – Time: Time the message was received by the detection server or endpoint client. These values map to the ‘Occurred On’ timestamp in the Endpoint Incident snapshot, which represents when the message was received by the detection server or endpoint client.
DLP Network Incident Message
Applicable cubes:
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Network Incident Message contains the following dimension attributes:
- Network Incident – Message Subject: Subject line of email message. In the case of a web violation, this will show as HTTP incident.
- Network Incident – Sender Name: Sender email address or IP address
DLP Network Incident Message Recipient
Applicable cubes:
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Network Incident Message Recipient contains the following dimension attributes:
- Network Incident – Recipient Domain: Recipient domain name or IP address
- Network Incident – Recipient Name: Recipient email address, IP address, or web address
DLP Network Incident Prevent Action
Applicable cubes:
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Network Incident Prevent Action contains the following dimension attributes:
- Network Incident – Prevent Action: Action taken by the Network Prevent server. Possible values are Blocked, Content Removed, Modified, Passed, and so on.
DLP Network Incident Protocol
Applicable cubes:
- DLP Network Incident Details
- DLP Network Incident Summary
- DLP Network Statistics
DLP Network Incident Protocol contains the following dimension attributes:
- Network Incident – Protocol: Network protocol name. Possible values are FTP, HTTP, HTTPS, SMTP, IM, and so on.
DLP Next Change Date
Applicable cubes:
- DLP Incident Status History
DLP Next Change Date contains the following dimension attributes:
- Next Change – Date: Date when the Incident Next Status value was changed.
If the status remains unchanged, this will show up as unknown
- Next Change – Date Range: Date range when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Day of Week: Day when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Month: Month when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Quarter: Quarter when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Week Number: Week number when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Year: Year when the Incident Next Status value was changed.
If the status remains unchanged, this will show up as unknown
DLP Next Change Time
Applicable cubes:
- DLP Incident Status History
DLP Next Change Time contains the following dimension attributes:
- Next Change – Hour: Hour when the Incident Next Status value was changed.
If the status remains unchanged, this will show up as unknown
- Next Change – Minute: Minute when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Second: Second when the Incident Next Status value was changed. If the status remains unchanged, this will show up as unknown
- Next Change – Time: Time when the Incident Next Status value was changed.
If the status remains unchanged, this will show up as unknown
DLP Next Change User
Applicable cubes:
- DLP Incident Status History
DLP Next Change User contains the following dimension attributes:
- Next Change – User: DLP user who set the Incident Next Status value
DLP Oracle Database
Applicable cubes:
- DLP Agent Status
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident History
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
- DLP Network Statistics
- DLP Policy History
- DLP User Actions Audit
- DLP Discover Scans
DLP Oracle Database contains the following dimension attributes:
- Oracle Database – Host Name: Denotes the Oracle database name and instance name from which the data is obtained
DLP Pattern Condition
Applicable cubes:
- DLP Policy History
DLP Pattern Condition contains the following dimension attributes:
- Patter Condition – Pattern: Regular expression defined within the Content Matches Regular Expression condition type
DLP Policy Details
Applicable cubes:
- DLP Endpoint Incident Details
- DLP Incident Details
- DLP Network Incident Details
- DLP Policy History
DLP Policy Details contains the following dimension attributes:
- Policy – Is Deleted: Indicates whether or not the policy has been deleted
- Policy – Description: Policy description as displayed in the Enforce console
- Policy – ID: Policy ID
- Policy – Is Latest Version: Indicates whether or not the policy version is the latest
- Policy – Name: Policy name
- Policy – Status: Indicates whether the policy is active or inactive
- Policy – Version: Policy version number
DLP Policy Group
Applicable cubes:
- DLP Discover Incident Details
- DLP Discover Incident Summary
- DLP Endpoint Incident Details
- DLP Endpoint Incident Summary
- DLP Incident Details
- DLP Incident Summary
- DLP Network Incident Details
- DLP Network Incident Summary
DLP Policy Group contains the following dimension attributes:
- Policy – Group Name: Policy Group names as defined in the Enforce console
DLP Policy Summary
Applicable cubes:
- DLP Discover Incident Summary
- DLP Discover Scans
- DLP Endpoint Incident Summary
- DLP Incident Status History
- DLP Incident Summary
- DLP Network Incident Summary
- DLP Network Statistics
DLP Policy Summary contains the following dimension attributes:
- Policy – Description: Policy description as displayed in the Enforce console
- Policy – ID: Policy ID
- Policy – Name: Policy name
- Policy – Status: Indicates whether the policy is active or inactive
DLP Protocol Condition
Applicable cubes:
- DLP Policy History
DLP Protocol Condition contains the following dimension attributes:
- Protocol Condition – Protocol: Protocol ID used within the Protocol or Endpoint Destination condition type
DLP Recipient Condition
Applicable cubes:
- DLP Policy History
DLP Recipient Condition contains the following dimension attributes:
- Recipient Condition – Email Address: Email address specified within the Recipient Matches Pattern condition type
- Recipient Condition – IP Address: IP address specified within the Recipient Matches Pattern condition type
- Recipient Condition – URL: URL specified within the Recipient Matches Pattern condition type
DLP Recipient Profile Condition
Applicable cubes:
- DLP Policy History
DLP Recipient Profile Condition contains the following dimension attributes:
- Recipient Profile Condition – DataSourceID: Data source ID for the directory profile
DLP Role
Applicable cubes:
- DLP Incident History
- DLP Incident Status History
- DLP Policy History
DLP Role contains the following dimension attributes:
- Role – Description: Role description as displayed in the Enforce console.
- Role – Name: Role name as displayed in the Enforce console
DLP Scan Started Date
Applicable cubes:
- DLP Discover Scans
DLP Scan Started Date contains the following dimension attributes:
- Scan Started – Date: Date the discover target scan started
- Scan Started – Date Range: Date range the discover target scan started
- Scan Started – Day of Week: Day the discover target scan started
- Scan Started – Month: Month the discover target scan started
- Scan Started – Quarter: Quarter the discover target scan started
- Scan Started – Week Number: Week number the discover target scan started
- Scan Started – Year: Year the discover target scan started
DLP Scan Started Time
Applicable cubes:
- DLP Discover Scans
DLP Scan Started Time contains the following dimension attributes:
- Scan Started – Hour: Hour the discover target scan started
- Scan Started – Minute: Minute the discover target scan started
- Scan Started – Second: Second the discover target scan started
- Scan Started – Time: Time the discover target scan started
DLP Sender Condition
Applicable cubes:
- DLP Policy History
DLP Sender Condition contains the following dimension attributes:
- Sender Condition – IP Address: IP address specified within the Sender/User Matches Pattern condition type
- Sender Condition – Sender Identifier: Email address, windows user name, or IM screen name specified within the Sender/user Matches Pattern condition type
DLP Sender Profile Condition
Applicable cubes:
- DLP Policy History
DLP Sender Profile Condition contains the following dimension attributes:
- Sender Profile Condition – DataSourceID: profile Data source ID for the directory
DLP Time Condition Created
Applicable cubes:
- DLP Policy History
DLP Time Condition Created contains the following dimension attributes:
- Condition Created – Hour: Hour the condition was created
- Condition Created – Minute: Minute the condition was created
- Condition Created – Second: Second the condition was created
- Condition Created – Time: Time the condition was created
DLP Time Condition Edited
Applicable cubes:
- DLP Policy History
DLP Time Condition Edited contains the following dimension attributes:
- Condition Edited – Hour: Hour the condition was edited (shows historical data)
- Condition Edited – Minute: Minute the condition was edited (shows historical data)
- Condition Edited – Second: Second the condition was edited (shows historical data)
- Condition Edited – Time: Time the condition was edited (shows historical data)
DLP Time Policy Created
Applicable cubes:
- DLP Policy History
DLP Time Policy Created contains the following dimension attributes:
- Policy Created – Hour: Hour the policy was created
- Policy Created – Minute: Minute the policy was created
- Policy Created – Second: Second the policy was created
- Policy Created – Time: Time the policy was created
DLP Time Policy Edited
Applicable cubes:
- DLP Policy History
DLP Time Policy Edited contains the following dimension attributes:
- Policy Edited – Hour: Hour the policy was edited (shows historical data)
- Policy Edited – Minute: Minute the policy was edited (shows historical data)
- Policy Edited – Second: Second the policy was edited (shows historical data)
- Policy Edited – Time: Time the policy was edited (shows historical data)
DLP Universal Metadata Condition
Applicable cubes:
- DLP Policy History
DLP Universal Metadata Condition contains the following dimension attributes:
- Universal Metadata Condition – Metadata Key: Indicates the type of the rule.
Possible values: NetworkLocation
- Universal Metadata Condition – Metadata Source: A constant value of 1.
- Universal Metadata Condition – Metadata Value: Indicates the endpoint location. Possible values: 0 and 1 where 0 = ‘On the corporate network’ and 1 = ‘Off the corporate network’
- Universal Metadata Condition – Metadata Value Operand: A constant value of ‘CSVSTRING’
DLP User Action
Applicable cubes:
- DLP User Actions Audit
DLP User Action contains the following dimension attributes:
- User Action – Category: Action taken when the event occurred
- User Action – Detail: Free text details for the event
- User Action – Entity: Object or component name on which the event occurred
- User Action – IP Address: IP Address of the PC that triggered the event
- User Action – Role: Role assigned to the user who triggered the event
- User Action – User Name: DLP user who triggered the event
DLP User Action Date
Applicable cubes:
- DLP User Actions Audit
DLP User Action Date contains the following dimension attributes:
- User Action – Date: Date the event occurred
- User Action – Date Range: Date range the event occurred
- User Action – Day of Week: Date of the week the event occurred
- User Action – Month: Month the event occurred
- User Action – Quarter: Quarter the event occurred
- User Action – Week Number: Week number the event occurred
- User Action – Year: Year the event occurred
DLP User Action Time
Applicable cubes:
- DLP User Actions Audit
DLP User Action Time contains the following dimension attributes:
- User Action – Hour: Hour the event occurred
- User Action – Second: Second the event occurred
- User Action – Minute: Minute the event occurred
- User Action – Time: Time the event occurred
DLP User Created By
Applicable cubes:
- DLP Policy History
DLP User Created By contains the following dimension attributes:
- User – Created By: DLP user who created the policy
DLP User Edited By
Applicable cubes:
- DLP Policy History
DLP User Edited By contains the following dimension attributes:
- User – Edited By: DLP user who modified the policy