GEODI logs all classification activity. The log format may be a database, CSV, CEF, or syslog. You may use a SIEM or Log Analysis Panel to analyze the logs.
GEODI Log Analysis Dashboard
Log Analysis shows and analyses classification activities using the log records.
The dashboard comes ready in a template project. Please follow the steps for dashboard activation.
A template project designed for classification is selected.
The project includes a directory/database containing pre-existing resources for classification logs.
You will see a DB data source; change DB settings to log DB.
If you don't have an existing database, you can use an SQLite file.
Any user in ACC.Classifier group will see the dashboard.
Save and Start indexing
GEODI will process the logs and the new ones.
Example Classification Panel
Log format settings and SIEM Applications
Logs may be in CSV, CEF, DB, or sent with syslog and compatible with SIEMs. Log settings are done on the classification policy manager.
CSV or CEF format
\AppData\Dece\Geodi\Workspaces<ProjectName>\Logs\DLPClassifier.
Optionally, it can also be saved in the Database.For other logs, you can check the GEODI Logs page.
File | UNCPath of classified content Örnek: C:\Users\<user>\Desktop\Yeni Microsoft Word Belgesi (2).docx |
---|---|
PreviousClass | Current Class (value = “?” for content without a class) |
Class | Given Class |
Source | Method of classification (Shell/Add-In) |
ClientIP | Client IP |
ClientUser | Client User Name |
Process Memory(Kb) | The memory used on the system at the time the log was written. |
Process Max Memory(Kb) | The peak of Memory usage in the system. |
AutoClass | If the AutoClass column is used as an automatic recommendation or forcibly, the ID value of the class determined automatically is provided. If automatic classification has never been used, it will be logged as empty. |
ActionType |
|
Database format
When the log format is DB, the following fields are also logged.
Object ID | Unique ID |
---|---|
Log Time | time of transaction |
Log User | user who doing the classification |
Log App | GEODI |
Log App Ver | GEODI Version |
Log Module | DLPClassifier |
Log Security Level | https veya http |
Log Level | medium |