Help Center
Quick Start
- Overview
- System requirements
- Minimum privileges required
- Default port configuration
- Installing DataSecurity Plus
- Uninstalling DataSecurity Plus
- Starting DataSecurity Plus
- Launching DataSecurity Plus
- Configuring your solution
- Licensing details
- Applying a license
File Auditing
- About File Auditing
- Domain configuration
- File server configuration
- Failover cluster configuration
- NetApp server configuration
- Nutanix server configuration
- EMC Isilon server configuration
- Workgroup configuration
- Amazon FSx configuration
Setting up File Audit
Dashboard
Reports
Alerts
Configuration
Storage Configuration
File Analysis
- About File Analysis
- Domain configuration
- File server configuration
- Workgroup configuration
- SMB File Server Configuration
- On-Demand Reports
Setting up File Analysis
Dashboard
Reports
Alerts
Configuration
Data Risk Assessment
- About Data risk assessment
Setting up Data risk assessment
Dashboard
Reports
Ownership analysis
Configuration
Endpoint DLP
- About Endpoint DLP
- Domain configuration
- Workstation configuration
- Device group configuration
- Workgroup workstation configuration
Setting up Endpoint DLP
Reports
Alerts
Prevention policies
Configuration
Cloud Protection
- About Cloud Protection
- Gateway Server Installation Steps
- Gateway Configuration in Endpoint
- Gateway Cluster Configuration
- Gateway Server Management
- Certificate Authority Configuration
- Two-way SSL configuration
- Manage Certificate Trust Store
- Threat Analytics Database
- Manage Banned Applications
- Manage Authorized Applications
- Regenerating gateway server access key
- Updating gateway server
- Gateway Server Failover
- Load Balancer Configuration
- Global Insight
- Application Insight
- User Insight
- Shadow Application Insight
- Banned Application Insight
- Cloud App Discovery
- Activity Overview
- File Transfer Insights
- Control Policies
- Application Insights
- Actor Insights
- Shadow App Discovery
- GenAI Insights
- Cyber Threat Analytics
- CIPA Compliance
Setting up Cloud Protection
Dashboard
Reports
Control Policies
Storage Configuration
Policy Management
Administrative settings
- Technician configuration
- Notification filters
- Manage agent
- Agent settings
- SIEM integration
- Business hours configuration
- Two-factor authentication
- Workgroup configuration
- Security policy
Email configuration
General settings
- Connection
- Personalize
- DataSecurity Plus Server
- Privacy Settings
- Disk utilization
- Schedule Retention Policy
Release notes
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
Troubleshooting
- HTTP communication failure
- Dormant DataEngine
- Secure Gateway server failure
- RPC communication failure
- Cloud Protection Gateway server failure
- Known issues and limitations
- Known errors and solutions
- Report discrepancy in File Analysis
Guides
- Agent document
- How to Migrate/Move DataSecurity Plus
- How to apply SSL certificate
- How to automate DataSecurity Plus database backup
- How to set alerts in DataSecurity Plus
- How to secure your DataSecurity Plus installation
Monitoring Settings
DataSecurity Plus provides predefined Monitoring Settings to help you detect and respond to endpoint security events in real time. Each setting is a configurable rule set that governs how endpoint activity is audited, alerted on, and responded to across your environment.
Monitoring Settings vs. DLP Policy Management: What's the difference?
Monitoring Settings govern endpoint-level activity such as auditing, alerting, and response actions, defining how file activity, removable device usage, and potential threats are tracked and responded to on workstations.
The DLP Policy Management, on the other hand, is purpose-built for detecting and enforcing prevention controls on sensitive data movement across data exit points such as email, identifying PII, PCI, ePHI, and other sensitive content and responding with Allow, Warn, or Block actions.
- Use Monitoring Settings when you need reactive visibility into endpoint activity. Auditing file accesses, alerting on threshold breaches, and responding to events as they occur.
- Use DLP Policy Management when you need proactive enforcement. Define and control what sensitive content can leave your endpoints.
Available Monitoring Settings
| Monitoring Settings | Description |
| Data Leak Prevention | Block pre-classified files as Restricted from leaving the network via USBs and email. |
| File Activity Monitoring | Monitor file accesses and changes on workstations via web, file share, and network share channels. |
| File Integrity Monitoring | Detect and respond to unauthorized changes made to business-critical files by users. |
| Potential Malware Intrusion | Detect potential malware by receiving alerts when safe threshold limits are breached. |
| Removable Device Auditing | Monitor all file-level activity occurring on USB storage devices. |
| Sensitive File Activity Monitoring and Response | Receive reports on user activities in pre-classified files often containing sensitive data such as PII and ePHI. |
Creating a new monitoring setting
Follow the steps below to create a new monitoring setting:
- Select Endpoint DLP from the application drop-down and navigate to Configuration > Monitoring Settings.
- Click + Monitoring Setting in the top-right corner.
- Name the setting and include an appropriate description.
- In the Applies To field, choose the device groups or individual workstations the setting should apply to.
- Choose the profiles you want to enforce from the Audit Profiles, Alert Profiles, and Global Restriction Profiles.
Example: To detect and alert on unauthorized changes to business-critical files, select the File Integrity Monitoring profile and configure the sensitive file paths you want to protect from Monitored Folders.
- Click Save.
Once saved, the new Monitoring Setting will be listed under Configuration > Monitoring Settings. Click the Edit icon next to any setting to modify the scope, audit, alert, and global restriction profiles, and click Save when done.
