12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Managing <strong>McAfee</strong> DLP systemsAdding servers to <strong>McAfee</strong> DLP systems 13Each of the user elements retrieves the following attributes.• User Name: user's name, alias, department, location• User Groups: user's group• User City: user's city• User Country: user's country• User Organization: user's company or organizationViewing Active Directory incidentsAll Active Directory incidents are reported to the dashboard.When Active Directory elements are used in a query, columns supporting the parameter are configuredin the search pop‐up and on the dashboard.When you get results from querying a directory server, you can view them on the <strong>Data</strong>‐in‐Motiondashboard or the corresponding ePolicy Orchestrator dashboard. Clicking the Columns icon will showyou what other data categories are available for display.Not all of these parameters can be used for queries. This accounts for the disparity of data categorieson search and rule pages.Search for user attributes in LDAP dataIf a directory server is registered to <strong>McAfee</strong> DLP Manager, you can search the imported data to findincidents by keying on user attributes.Directory server data can be searched by source or destination IP and/or port.Use Basic Search to do exploratory searches, and Advanced Search to create complex searches or rules.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting.• On your <strong>McAfee</strong> DLP appliance, select Capture.2 Click either Basic Search or Advanced Search.3 From the Basic Search | Input Type or Advanced Search | Source/Destination menu, select a user attribute.4 Click Search or Save as Rule.Find user attributes in LDAP dataIf a directory server is registered to <strong>McAfee</strong> DLP Manager, you can use the imported data to findincidents by keying on the user attributes.Before you beginOne or more dashboards must display incidents retrieved from a directory server attachedto the <strong>McAfee</strong> DLP system.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 267

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!