1 Reply Latest reply on Feb 21, 2017 1:27 PM by j58574748

    Problem with email protection rule using text pattern - DLP 10

    arranda.saputra

      I have defined two lists of keyword, say "Keyword 1" and "Keyword 2"

       

      Then I created a Classification rule to match "Keyword 1 AND Keyword 2", i named this rule as "My Classification Rule"

       

      Then I apply the classification to an email protection rule, I named it "Email Classification Rule" and I created a condition to block if "one of the email elements" contains text pattern inside "My Classification Rule"

       

      My expectation:

      If I have an attachment that only contains pattern from keyword 1 -> expected not blocked -> result is as expected

      If I have an attachment that only contains pattern from keyword 2 -> expected not blocked -> result is as expected

      If I have message body that only contains pattern from keyword 1 -> expected not blocked -> result is as expected

      If I have message body that only contains pattern from keyword 2 -> expected not blocked -> result is as expected

      If I have an attachment that contains any pattern from both keyword 1 and keyword 2 -> expected blocked -> result is as expected

      If I have message body that contains any pattern from both keyword 1 and keyword 2 -> expected blocked -> result is as expected

      If I have keyword 1 in attachment and keyword 2 in message body -> expected blocked -> result not as expected

      If I have keyword 2 in attachment and keyword 1 in message body -> expected blocked -> result not as expected

       

      It looks like DLP is not combining the content analysis result from attachment and message body, despite the fact i have choose "one of the email elements" in the condition.

       

      Please kindly advise