View DLP for Drive dashboard incidents, alerts, and audit events

Use the Security Dashboard, alerts, and the Rule log events for DLP for Drive

Supported editions for this feature: Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Fundamentals, Education Standard, and Education Plus; Enterprise Essentials Plus. Compare your edition

Data loss prevention (DLP) for Drive detects incidents through scans, and incidents trigger actions and alerts.

The reports described in this article apply to DLP for Drive only.

Note: If you have Education Fundamentals, you can access and manage data protection rules in Security and then Access and data control and then Data protection.

DLP Security Dashboard incidents

View DLP logged incidents detected during DLP scans in Security and then Dashboard. From the Security Dashboard, you can see these incident dashboards (with incidents logged over time):

  • DLP Incidents
  • Top Policy Incidents

You can triage daily incidents and examine trends to discover the success of implemented DLP policies. Details on single or aggregated incidents are available to help you respond quickly to events, and helps you measure policy success over time. Go to About the security dashboard for details.

DLP alerts

If you configure alerts for rules, you receive a DLP alert in the alert center when a data protection rule is triggered. From the Admin console Home page, go to Security and then Alert center. Under the alert Key details, the system records only recipients that were matched before a data protection rule flags the content. Re-sharing a document after it is flagged by DLP does not automatically update the recipient information on the alert.

Note: There is a time lag between when an alert is created in the Alert center and when the corresponding incident or log event is shown in the DLP Security Dashboard and the security investigation tool.

Each rule can generate up to 50 alerts per rule per day. Incidents for each rule are recorded in the alert center and the Rule log events. For details, go to View alert details and Rule log events.

DLP audit events

The Rule log events show a record of DLP incidents recorded in your Google Admin console. For example, you can see when a user has tried to share sensitive data such as a driver's license number. Go to Rule log events for details. Audit events are also shown in the investigation tool, where DLP individual incidents are shown under Rule log events. Both the Rule log events and the investigation tool will surface the audit logs for triggered data protection rules.