DLP recipient field is "Unknown"
search cancel

DLP recipient field is "Unknown"

book

Article ID: 176293

calendar_today

Updated On:

Products

CASB Security Advanced Data Loss Prevention Cloud Detection Service

Issue/Introduction

The "recipient" field shows unknown in the DLP incidents [DLP Enforce]

Environment

DLP is integrated with CloudSOC, and the CloudDetector is successfully receiving activity from CloudSOC. A policy is created in DLP for Share activities. 

Cause

The "recipient" field is based on email activity. Sharing does not include this field. Share activity includes a field called "Shared with" instead. 

This is true for any activity that does not include a "recipient" field.

Resolution

Policies for share activity should be based on the "shared with" attribute instead of "recipient" field. 
 Other activity's like upload will also have recipient field as unknown.

You may see the recipient field populated if it has been shared.