The enforce server is only showing the lookup attribute data for email events and does not populate for web based incidents. Detection is being done on web uploads such as http/https monitoring. Incident is generated on the web upload has a username, but not a email address.
DLP Network Monitor on Redhat Linux 5.2 OS. Detection done with SMTP and HTTP/HTTPS web uploads.
The incident generated from the web upload does not contain an email address only user name. Custom attributes will not populate unless an email is associated with the incident.
Data Loss Prevention is working as designed. If custom attributes needs to be populated based off username then a custom script lookup plugin will need to be created. Engage professional services for any assistance with the custom script lookup plugin.