Classifier Logs and Log Analysis Panel

Classifier Logs and Log Analysis Panel

The Classification and Log Analysis Panel is installed automatically with the Classification Module. The 0000-Classifier project is provided with ready-to-use log analysis and dashboards.

 

If you want to use external tools for log analysis, you can configure log settings to enable Syslog or other supported formats. Logs may be in CSV, CEF, Syslog, or Database. For Syslog support, select DB as the log format, choose Syslog Connection as the VT provider, and enter the values for the listening application.

 

With the Log Analysis Panel, you can monitor classification activities and perform analysis based on users and classes. Any user in the ACC.Classifier group can access the dashboard.


image-20240229-074649.png
image-20240229-074845.png
image-20240229-074910.png

Classifier Log Fields

  • For other logs, you can check the GEODI Logs page.

Object ID

Unique ID

Log Time

Time of transaction

Log User

The user who is doing the classification

Log App

GEODI

Log App Ver

GEODI Version

Log Module

DLP Classifier

Log Security Level

https:// veya http://

Log Level

medium

File

UNCPath of classified content

Example: C:\Users\<user>\Desktop\New Word Doc (2).docx

Previous Class

Current Class (value = “?” for content without a class)

Class

Given Class

Source

Method of classification (Shell/Add-In)

Client IP

Client IP

Client User

Client Username

AutoClass

If the AutoClass column is used for automatic recommendations or forced recommendations, the ID of the automatically determined class is provided. If automatic classification has never been used, it will be logged as empty.

AutoClassReason

The findings that trigger the autoclass. You must enable this log from the policy page.

Action Type

  • Auto: Automatically assigned class.

  • Manuel: Manual class selected.

  • Offline: Manual class selected. (GDE and Shell)

  • AUTOCLASS Body Email: Classified as auto with %AUTOCLASS% text in Outlook desktop.

  • Auto Menu Click: Classified by automatic clicking on the Add-In.

  • Class Menu Click: Classified by selecting a class through the Add-In.

  • Form UI: Form interface opened, selection made through the form.

  • Forced AutoClass: It was forced to be automatic. Automatic classification was enforced.

 

Syslog support

For Syslog support, select DB as the log format, choose Syslog Connection as the VT provider, and enter the values for the listening application.