Hi communities,
I am running an issue for now. I try to capture all events which are in violation of the configured policies.
Using the document classification feature of the CA DATAMINDER i can capture all events containing some keywords defined into the document classification.
The CFSA can detect files being copied from the local drive to network locations , but it doesn't capture these files when being copied from the network locations into the local drive (C OR D).
I have tried to include the C and D as removable devices, howerver the issue is still running. I configured this by going to the client common policies and in the "target as removable devices" i include "C:/" and "D:/", but it doesn't function.
Kindly asking for your help
Thanks and best regards
Hi ANDA_15
Let say a endpoint node "A" is not allow to share a classified document on a UNC \\myshare\demo, have you configured the policy to control endpoint node "A" to copy classified data FROM that UNC? It would be easy if you share more details about policy you configured.
Regards,