How to Summarize Cloud DLP Incidents by File Extension
search cancel

How to Summarize Cloud DLP Incidents by File Extension

book

Article ID: 445603

calendar_today

Updated On:

Products

CASB Security Standard Data Loss Prevention

Issue/Introduction

You want to identify which file types (extensions) are generating the highest number of DLP incidents. This data helps you investigate potential risks and fine-tune your DLP policies accordingly.

Environment

 

  • Platform: CloudSOC

  • Feature: Cloud DLP / Analyzer

 

 

Resolution

You can use the Analyzer tool in CloudSOC to aggregate and summarize incident data by file extension.

Step-by-Step Instructions

  1. Log in to the CloudSOC console.

  2. Navigate to Analyze > Analyzer.

  3. In the left-hand panel, expand Cloud DLP, locate Incident Count, and click Add to measure.

  4. Next, expand the Common section in the same panel.

  5. Hover over File Extension and click Add to Rows.

Result: The console will generate a data table displaying all detected file extensions alongside the exact number of incidents each one has triggered.

 

Pro Tip: Deepen Your Analysis

To get even more granular insights, you can add multiple dimensions to your rows.

  • Add more filters: In the left-hand panel, hover over other attributes—such as User, Policy, or Service—and click Add to Rows.

  • Why do this? This allows you to cross-reference your data and see exactly which users or which policies are triggering incidents for specific file extensions.