You can set an incident task to generate an automated email for the incident that was created by your protection rule (rule criteria for 'rule name', 'rule set name', 'policy name', etc.). These are configured in your incident manager and discussed more in depth on starting on page 115 of the 9.4 product guide.
Yes I Know this function
But I don't know how to set the criteria.
Because file copy is 1 file 1 event, I don't know how to handle