Can the DLP Endpoint agent detect and report the source file directory (and destination directory where applicable) when a file is uploaded to an external site using a browser?
Today, this is only captured for removable media.
Other channels do not report the source file directory in the console or report.
When incidents are exported, the only incidents with this information are removable media
However, the columns exist when exporting events into a CSV file.
This is working exactly as designed, for HTTP equally as for HTTPS.
In neither case is the source file data included in the incident payload, and the incident snapshots don't support the display of said data.
A feature request has been submitted to add this functionality.