You want to identify which file types (extensions) are generating the highest number of DLP incidents. This data helps you investigate potential risks and fine-tune your DLP policies accordingly.
Platform: CloudSOC
Feature: Cloud DLP / Analyzer
You can use the Analyzer tool in CloudSOC to aggregate and summarize incident data by file extension.
Log in to the CloudSOC console.
Navigate to Analyze > Analyzer.
In the left-hand panel, expand Cloud DLP, locate Incident Count, and click Add to measure.
Next, expand the Common section in the same panel.
Hover over File Extension and click Add to Rows.
Result: The console will generate a data table displaying all detected file extensions alongside the exact number of incidents each one has triggered.
To get even more granular insights, you can add multiple dimensions to your rows.
Add more filters: In the left-hand panel, hover over other attributes—such as User, Policy, or Service—and click Add to Rows.
Why do this? This allows you to cross-reference your data and see exactly which users or which policies are triggering incidents for specific file extensions.