Help Center

Third-party software Contact us

Monitoring Settings

DataSecurity Plus provides predefined Monitoring Settings to help you detect and respond to endpoint security events in real time. Each setting is a configurable rule set that governs how endpoint activity is audited, alerted on, and responded to across your environment.

Monitoring Settings vs. DLP Policy Management: What's the difference?

Monitoring Settings govern endpoint-level activity such as auditing, alerting, and response actions, defining how file activity, removable device usage, and potential threats are tracked and responded to on workstations.

The DLP Policy Management, on the other hand, is purpose-built for detecting and enforcing prevention controls on sensitive data movement across data exit points such as email, identifying PII, PCI, ePHI, and other sensitive content and responding with Allow, Warn, or Block actions.

  • Use Monitoring Settings when you need reactive visibility into endpoint activity. Auditing file accesses, alerting on threshold breaches, and responding to events as they occur.
  • Use DLP Policy Management when you need proactive enforcement. Define and control what sensitive content can leave your endpoints.

Available Monitoring Settings

Monitoring Settings Description
Data Leak Prevention Block pre-classified files as Restricted from leaving the network via USBs and email.
File Activity Monitoring Monitor file accesses and changes on workstations via web, file share, and network share channels.
File Integrity Monitoring Detect and respond to unauthorized changes made to business-critical files by users.
Potential Malware Intrusion Detect potential malware by receiving alerts when safe threshold limits are breached.
Removable Device Auditing Monitor all file-level activity occurring on USB storage devices.
Sensitive File Activity Monitoring and Response Receive reports on user activities in pre-classified files often containing sensitive data such as PII and ePHI.

Creating a new monitoring setting

Follow the steps below to create a new monitoring setting:

  • Select Endpoint DLP from the application drop-down and navigate to Configuration > Monitoring Settings.
  • Click + Monitoring Setting in the top-right corner.
  • Name the setting and include an appropriate description.
  • In the Applies To field, choose the device groups or individual workstations the setting should apply to.
  • Choose the profiles you want to enforce from the Audit Profiles, Alert Profiles, and Global Restriction Profiles.

    Example: To detect and alert on unauthorized changes to business-critical files, select the File Integrity Monitoring profile and configure the sensitive file paths you want to protect from Monitored Folders.

  • Click Save.

Once saved, the new Monitoring Setting will be listed under Configuration > Monitoring Settings. Click the Edit icon next to any setting to modify the scope, audit, alert, and global restriction profiles, and click Save when done.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.