FAQs on Data Explorer
- ► What are Objects in DSPM Data Explorer?
- In Data Explorer, an Object refers to any instance of data assets and resources that the system identifies and monitors within your infrastructure. For example, objects are individual files such as documents, spreadsheets, presentations, archives, etc, stored in CSPs or cloud storage. Or the Objects can also be email conversations or a web post, which involves a file. These objects are identified through scans, such as classification scans that detect Personally Identifiable Information (PII), Payment Card Information (PCI), Protected Health Information (PHI), secrets, and other types of sensitive data. Once identified, Data Explorer allows you to view, filter, and analyze these objects to understand where sensitive data resides and how it is exposed across your environment.
- ► How does Data Explorer detect and capture your Data?
- Data Explorer monitors data activity and captures objects that are scanned against your organization's DLP policies and classifications. This ensures that a detailed record is maintained in Data Explorer, even if an incident is not specifically triggered. Data Explorer collects information on objects from various sources, including:
- ODS Scans. On-demand or scheduled scans of an organization's data sources.
- NRT (Near Real-Time) Scans of Sanctioned Services. Continuous monitoring of sanctioned cloud services for policy violations.
- Emails. Scans email attachments for sensitive information or policy violations.
- Web Uploads. Scans and captures sensitive objects from files uploaded via web browsers.
- ► What does Data Explorer Record?
- Data Explorer records information across the following types of data:
- Files exceeding 256 bytes in size.
- Objects that are embedded within other objects.
- A file compressed in a zip, a document included in a presentation, etc
- Files uploaded to the CSP.
- Files within Web Posts.
- Emails that contain file attachments. An email without attachments will not be recorded in Data Explorer.
- A chat message without an attached file will not be captured. For example,
- A chat message posted directly in a web browser, without an attached file, will not be captured in Data Explorer.
NOTE: The number of Data Explorer events is limited per transaction, and the current transaction limit for Data Explorer events is 1000. For example, if you have a zip file containing 1001 files, Data Explorer only records 1000 files.
