Download evidence files for DLP alerts
Download files that violate the DLP policy on provider that supports ICAP. Download this file onto your local machine from the DLP IR Analyst workspace and DLP IR End user workspace for approvers.
Before you begin
Role required:
- sn_dlir.analyst and approvers can download
About this task
You need to enable file download for ICAP before moving ahead.
Procedure
Navigate to All > ICAP DLP Integration > Settings.
Enable the property sn_icap_dlp.enable_file_download Enabling this property allows downloading the evidence file of the reported ICAP incident.
You will be able to see the Download File button on the DLP IR Analyst Workspace and DLP IR End user workspace.
Navigate to All > DLP Incident Management > DLP Analyst Workspace.
Open a DLP incident record which is ingested from ICAP provider source.
Click Download File.
Note: DLP admin can control the access of Download File action for all integrations by disabling the Should downloading the violating file of the reported incident be allowed option from the Advanced Settings page of DLP Administration. For more information, see Configure advanced settings.
Parent Topic:Internet Content Adaption Protocol (ICAP) integration for DLP IR