Duplicate DLP incidents while exporting using Query
Can someone sort out my issue with respect to Duplicate DLP incidents. When i checked DLP incident count of Email protection in DLP incident manager, it shows around 400 for past 24 hours. But when i exporting the DLP incident dump for email protection for past 24 hours, it gives around 30000 incidents.
After checking the incident dump, i got to know that Incident ID's are duplicate but evidence file different. I know its little confusing right, checked one incident ID in which user has sent around 20 attachment beacuse of this i'm getting huge number of duplicate incidents for one incident.
i would be more helpful if someone will solve my issue.