Limit how much of the incident detail is retained
search cancel

Limit how much of the incident detail is retained


Article ID: 159786


Updated On:


Data Loss Prevention Endpoint Prevent Data Loss Prevention Network Monitor Data Loss Prevention Network Prevent for Email Data Loss Prevention Enforce Data Loss Prevention Network Discover Data Loss Prevention Network Protect Data Loss Prevention Endpoint Discover Data Loss Prevention


How can you limit the retained incident data, for example the SMTP message that triggered an incident?


Set up a response rule to limit the retained data:

  1. Create a response rule.
  2. Set the action to "All: Limit Incident Data Retention".
  3. Enable "Discard Original Message" and select which data can be deleted (all, attachments w/ no violations, none).


Listed below are the default behaviors for the various DLP Servers: 

  • Endpoint and Endpoint Discover: does not retain original file by default
  • Network Discover:  There is no way to retain the original file
  • All other Servers:  Default behavior is to retain everything