{"id":5492,"date":"2022-03-24T17:08:48","date_gmt":"2022-03-24T14:08:48","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=5492"},"modified":"2022-04-05T14:12:58","modified_gmt":"2022-04-05T11:12:58","slug":"using-the-limit-reporting-function","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/using-the-limit-reporting-function\/","title":{"rendered":"Using the \u2018Limit Reporting\u2019 Function"},"content":{"rendered":"<div class=\"preformatted-content\">\n<p>TL;DR<\/p>\n<ul>\n<li aria-level=\"1\">Large volumes of data can overwhelm Administrators when running reports.<\/li>\n<li aria-level=\"1\">The <strong>Limit Reporting<\/strong> feature makes reports more digestible by restricting reported items to the threshold applied in the corresponding policy.<\/li>\n<li aria-level=\"1\">Further analysis can be made after enabling File Shadowing. This maintains a copy of the transmitted file, allowing Administrators to inspect the content.<\/li>\n<\/ul>\n<\/div>\n<p>For Administrators who need to audit their environment, fine-tune their policies, and stay on top of their DLP strategy, the large volumes of data being processed and transmitted can quickly become overwhelming. This is where Endpoint Protector\u2019s <strong>Limit Reporting<\/strong> feature steps in; reducing the reporting burden while not leaving gaps in overall auditability or data loss prevention.<\/p>\n<p>The <strong>Limit Reporting<\/strong> feature, as the name suggests, limits the amount of entries displayed in your Audit Reports while providing a function for deeper analysis through Endpoint Protector\u2019s File Shadowing feature.<\/p>\n<p>Once <strong>Limit Reporting<\/strong> is configured, your reports will adhere to the threshold limit that has been applied to the corresponding policy. For example, if you have a Content Aware Protection policy threshold configured at \u20181\u2019 you will see one entry in your Content Aware Protection Report, even if that file contains five hundred entries of sensitive data.\u00a0 If you have the threshold configured at \u201810\u2019 then only the first ten entries identified within the file will be displayed.<\/p>\n<p>If further investigation is needed (perhaps a look at the actual content of a transmitted file), <strong>File Shadowing<\/strong> offers the ability to look at a copy of the original file transmitted.\u00a0 This may be useful in determining more specifics around why it was necessary for a user to attempt to send the file object.<\/p>\n<h2>Enabling Limit Reporting<\/h2>\n<p>To enable \u2018Limit Reporting\u2019, login to the Endpoint Protector Management Console and scroll down on the left Navigation bar to find <strong>Device Control<\/strong> &gt; <strong>Global Settings<\/strong>.\u00a0 Select this, and on the right-hand side find the toggle for <strong>Limit Reporting<\/strong> &#8211; &#8211; turn this to ON.\u00a0 After doing so, be sure to scroll down and click the <strong>Save <\/strong>button.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5493\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-560x257.png\" alt=\"\" width=\"560\" height=\"257\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-560x257.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-1024x470.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-768x352.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-1536x705.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-2048x940.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/LimitReporting-1568x720.png 1568w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<h2>Set a policy threshold<\/h2>\n<p>Enabling the Limit Reporting function allows for the amount of entries defined within your policy thresholds to align with the amount of entries seen in your Audit Reporting.\u00a0 To review your thresholds, locate your policies for <strong>Content Aware Protection<\/strong> and review the <strong>Thresholds<\/strong> section.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5494\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-560x171.png\" alt=\"\" width=\"560\" height=\"171\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-560x171.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-1024x313.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-768x235.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-1536x469.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-2048x625.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/Thresholds-1568x479.png 1568w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<p>After these updates have been performed, you will see an overall reduction in the number of entries within the Content Aware Protection report &#8211; making it lighter weight and easier to use for auditing purposes.<\/p>\n<p>Below is a sample set of entries after applying a threshold of \u20181\u2019 within a Content Aware policy. Each of these transmitted files contained approximately fifty entries which would have been deemed sensitive enough to trigger a policy violation.\u00a0 However, with <strong>Limit Reporting<\/strong> enabled, the reporting dashboard offers a simpler, condensed view, while still offering enough information to consider further investigation and a potential blocking strategy for this endpoint.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5495\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-560x191.png\" alt=\"\" width=\"560\" height=\"191\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-560x191.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-1024x349.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-768x262.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-1536x524.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-2048x698.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/ReportWithLimits-1568x535.png 1568w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<h2>Enable File Shadowing<\/h2>\n<p>If there is a need to enable \u2018File Shadowing\u2019, this is found further down in the Global Settings section of Device Control.\u00a0 File Shadowing presents a copy of the file(s) being transmitted.\u00a0 Please note that File Shadowing may require an increase in the storage space used by your Endpoint Protector Server.\u00a0 Having a strategy of log rotation or general management should be considered when enabling the <strong>File Shadowing<\/strong> feature.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5496\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-560x145.png\" alt=\"\" width=\"560\" height=\"145\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-560x145.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-1024x266.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-768x199.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-1536x398.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-2048x531.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/03\/FileShadowing-1568x407.png 1568w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<h2>Need help?<\/h2>\n<p>If you\u2019d like further information and guidance on the Limit Reporting feature or File Shadowing, please reach out to your Customer Success Manager or <a href=\"https:\/\/support.endpointprotector.com\/hc\/en-us\/requests\/new\" target=\"_blank\" rel=\"noopener\">get in touch with our support team here.<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TL;DR Large volumes of data can overwhelm Administrators when running reports. The Limit Reporting feature makes reports more digestible by restricting reported items to the threshold applied in the corresponding policy. Further analysis can be made after enabling File Shadowing. This maintains a copy of the transmitted file, allowing Administrators to inspect the content. For &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/using-the-limit-reporting-function\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Using the \u2018Limit Reporting\u2019 Function&#8221;<\/span><\/a><\/p>\n","protected":false},"author":8,"featured_media":5578,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=5492"}],"version-history":[{"count":14,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5492\/revisions"}],"predecessor-version":[{"id":5579,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5492\/revisions\/5579"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/5578"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=5492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=5492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=5492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}