DLP policy for CASB Custom Gatelet failing to detect
search cancel

DLP policy for CASB Custom Gatelet failing to detect

book

Article ID: 232588

calendar_today

Updated On:

Products

Data Loss Prevention Enterprise Suite Data Loss Prevention

Issue/Introduction

DLP is not doing content inspection with CASB Gatelet.

No incident is created.  

Cause

Cause is likely policy or custom gatelet identifier.

Resolution

First verify the custom gatelet name is correct. 

One way to do this is in CASB to review the incident and pull the "Original Message" and look at the contextual attribute in the JSON.

For a custom gatelet it must match exactly case sensitive. For example LinkedIn is: gatelet.linkedin

 

A secondary issue may be the policy in DLP. 

Confirm that the policy is not just set to search the header. Ensure the policy is set to the body. The reason for this is if you are scanning only the header for SSN or other data it wont find anything and the data you are searching for will not be tagged.

Additionally if you have a CASB policy in place that searches for the same data or is a blanket policy which blocks uploads, and your DLP policy is supposed to scan uploads the DLP policy will not be hit. Since the order of Operation is CASB -> DLP.