Hello,
I have a significant number of Notables raised by the Non-pdm alerts correlation search.
The correlation search runs every 2 hours, triggers an alert when the user violates the policy
sourcetype=netskope earliest=-2h NOT (alert_name IN ("pdm", " External_Shared Files - Alert", "All DLP Policies"))
| stats dc(alert_name) as alert_count,values(_time) as incident_time by user
Throttling is set to 3 days duration what changes we need to make a less no. of notables to be raise?
Thanks..
You have a few options.
1) Train the users to not violate policy
2) Adjust policy to better reflect what users need to do
3) Modify the CS to filter out "uninteresting" events