Classifier Logs and Log Analysis Panel
The Classification and Log Analysis Panel is installed automatically with the Classification Module. The 0000-Classifier project is provided with ready-to-use log analysis and dashboards.
If you want to use external tools for log analysis, you can configure log settings to enable Syslog or other supported formats. Logs may be in CSV, CEF, Syslog, or Database. For Syslog support, select DB as the log format, choose Syslog Connection as the VT provider, and enter the values for the listening application.
With the Log Analysis Panel, you can monitor classification activities and perform analysis based on users and classes. Any user in the ACC.Classifier group can access the dashboard.
Classifier Log Fields
For other logs, you can check the GEODI Logs page.
Object ID | Unique ID |
|---|---|
Log Time | Time of transaction |
Log User | The user who is doing the classification |
Log App | GEODI |
Log App Ver | GEODI Version |
Log Module | DLP Classifier |
Log Security Level | https:// veya http:// |
Log Level | medium |
File | UNCPath of classified content Example: C:\Users\<user>\Desktop\New Word Doc (2).docx |
Previous Class | Current Class (value = “?” for content without a class) |
Class | Given Class |
Source | Method of classification (Shell/Add-In) |
Client IP | Client IP |
Client User | Client Username |
AutoClass | If the AutoClass column is used for automatic recommendations or forced recommendations, the ID of the automatically determined class is provided. If automatic classification has never been used, it will be logged as empty. |
AutoClassReason | The findings that trigger the autoclass. You must enable this log from the policy page. |
Action Type |
|
Syslog support
For Syslog support, select DB as the log format, choose Syslog Connection as the VT provider, and enter the values for the listening application.