Reference Guide

Security Management Server v10.2.7 AdminHelp
113
1. In Moniker, select Protected Office and Beacon.
2. In the global map view, drill in to a marker cluster in an unexpected location and select a blue
marker.
3. Select the Show only visible check box for the columns to list only the files for that audit event.
4. Click
next to a Device, User, File Name, or File KeyID.
For example, click
next to a user name, then click next to a file name to zoom to the map
location of the specified user when a specified file was accessed.
5. Analyze the data in the Management Console or click Export File > Excel or CSV where you
can sort the data. Optionally, you can export the audit events to a SIEM server.
6. Clear Search and press Enter to return to the global map view.
Audit Cloud Encryption (Mac or mobile)
To audit protected .xen files only:
1. In Moniker, select Cloud Encryption.
2. In More, select Action and Cloud Action.
3. Initially, in Columns, select Device, User, Timestamp, File KeyID, Provider, Action, and Cloud
Action.
Default Monikers and Columns
If you leave the defaults, all monikers and columns display. Select one item from Grouping to sort
monikers or column options. Select options to minimize the data that displays.
EU General Data Protection Regulation (GDPR)
For privacy laws in Europe, you can disable audit events. See Enterprise > Global Settings > Settings
> Web Portal Audit Policies.
View Audit Events (Geolocation)
Click Audit Events in the left pane to view geographic map points of file events on computers and
devices running Data Guardian.
For a list of audit event types, see Data Guardian and Audit Events
.
For information about exporting audit events to a SIEM server, see Export Events to SIEM Server.
Map points are color coded to indicate the number of audit events in a location:
Map point represents a single event
Fewer than 10 events
More than 10 events