Using Symantec Data Loss Prevention (DLP) Network Prevent for Web some incidents are not creating incidents when they should.
Policy may have on and off-network response rules. Or DLP Network Prevent for Web may ignore content less than 4k in size.
If you are using Symantec Website Security (WSS) you can check "Ignore requests smaller than" in Advanced Settings for DLP Network Prevent for Web Detector. If you have a Cloud Detector you may need to create a support request to have changes made by the Cloud team. This will set contents to be 4k minimum size to be scanned by DLP. If you view all content then performance will be much slower than desired.
You can specify based on whether on or off the network in your policy too. DLP policy response rules can be different for on-network versus off-network. So, double check your policies.