Setting DLP Rule Tracking

A primary consideration for creating Data Loss PreventionClosed Check Point Software Blade on a Security Gateway that detects and prevents the unauthorized transmission of confidential information outside the organization. Acronym: DLP. rules is how to audit incidents.

In the rule baseClosed All rules configured in a given Security Policy. Synonym: Rulebase. of the Data Loss Prevention policy, the Track column offers these options:

Option

Meaning

Email

Sends an email to a configured recipient

Log

Records the incident in the Logs & Monitor view (All the other tracking options also log an incident).

Alert

Opens a pop-up window in the SmartView Monitor.

SNMP Trap

Sends an SNMP alert to the SNMP GUI. This uses the fwd process, to run the internal_snmp_trap script that sends an ID, the trap type, source port, community, and host name.

User Defined (alert)

Sends one of three possible customized alerts. The alerts are defined by the scripts specified in the main Menu > Global Properties > Log and Alert > Alert Commands. The alert process on the Log server runs the scripts.

Store Incident

Determines how the data should be stored and deleted (if at all). The options are:

  • Yes

  • Only as text

  • Don't store (depending on other conditions)

  • Delete

Store Incident

Store Incident tracking options determine how data that matches a DLP ruleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. is stored (or not stored).