Supported editions for this feature: Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Fundamentals, Education Standard, and Education Plus; Enterprise Essentials Plus. Compare your edition
Data loss prevention (DLP) for Drive detects incidents through scans, and incidents trigger actions and alerts.
The reports described in this article apply to DLP for Drive only.
Note: If you have Education Fundamentals, you can access and manage data protection rules in
Security Access and data control
Data
protection.
DLP Security Dashboard incidents
View DLP logged incidents detected during DLP scans in Security
Dashboard. From the Security Dashboard, you can see these incident dashboards
(with incidents logged over time):
- DLP Incidents
- Top Policy Incidents
You can triage daily incidents and examine trends to discover the success of implemented DLP policies. Details on single or aggregated incidents are available to help you respond quickly to events, and helps you measure policy success over time. Go to About the security dashboard for details.
DLP alerts
If you configure alerts for rules, you receive a DLP alert in the alert center
when a data protection rule is triggered. From the Admin console Home page, go
to Security Alert center.
Under the alert Key details, the system records only recipients that were
matched before a data protection rule flags the content. Re-sharing a document after it is
flagged by DLP does not automatically update the recipient information on the
alert.
Note: There is a time lag between when an alert is created in the Alert center and when the corresponding incident or log event is shown in the DLP Security Dashboard and the security investigation tool.
Each rule can generate up to 50 alerts per rule per day. Incidents for each rule are recorded in the alert center and the Rule log events. For details, go to View alert details and Rule log events.
DLP audit events
The Rule log events show a record of DLP incidents recorded in your Google Admin console. For example, you can see when a user has tried to share sensitive data such as a driver's license number. Go to Rule log events for details. Audit events are also shown in the investigation tool, where DLP individual incidents are shown under Rule log events. Both the Rule log events and the investigation tool will surface the audit logs for triggered data protection rules.