Showing results for 
Show  only  | Search instead for 
Did you mean: 

Is it possible to only count Advanced Patterns as hits, but still require dictionary thresholds?

I'm wondering if there is anyway to only count the advanced patterns as hits in a incident, but still require a threshold of dictionary words to match with a advanced pattern before it is flagged at all.

The reason for this, is to avoid documents that have one or two sample social security numbers, but it uses the phrase SSN or Social Security a hundred times.

I'm currently using DLPe 9.3, we'll be migrating to version 11 later this year as well. Any suggestions or help would be appreciated as not being able to do this flags way too many false positives to get much use from scanning end point documents.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community