DLP recipient field is "Unknown"
search cancel

DLP recipient field is "Unknown"

book

Article ID: 176293

calendar_today

Updated On:

Products

CASB Security Advanced Data Loss Prevention Cloud Detection Service

Issue/Introduction

The "recipient" field shows unknown in the DLP incidents [DLP Enforce]

Environment

DLP is integrated with CloudSOC, and the CloudDetector is successfully receiving activity from CloudSOC. A policy is created in DLP for Share activities. 

Cause

The "recipient" field is based on email activity. Sharing does not include this field. Share activity includes a field called "Shared with" instead. 

This is true for any activity that does not include a "recipient" field.

Resolution

Policies for share activity should be based on the "shared with" attribute instead of "recipient" field. 
 Other activity's like upload will also have recipient field as unknown

Attachments