Reference Guide
Dell Security Center v10.2.7 AdminHelp
59
Note: Files that lack geolocation data and display only in the columns still provide some information for
auditing.
• Show only visible check box - If you click a marker cluster, the map only displays the area for
that cluster, but the columns list all audit events in the original query. Select the check box on
the lower right for the columns to only list audit events for those visible map points. As you
continue to drill down, the columns only list the events for the visible map points. Clear the
check box to return to the global view.
Audit Event Options and Filters
Use these options to determine the type and amount of audit event data to display.
• Moniker - By default, information displays for all monikers. Select one or more check boxes to
display specific monikers. Click Clear selected items to display all.
• Cloud Encryption - applies to:
• Cloud Encryption (Mac, mobile and web portal; Windows Data Guardian
v2.3 and earlier)
• Cloud_Access_Security_Broker (CASB) (web portal 2.9 and higher)
• Basic File Protection (web portal 2.9 and higher with CASB, when a .xen
file event is created)
• Protected Office (Windows, Mac, mobile, and web portal) - also applies to
Cloud_Access_Security_Broker
• System - Populates the user logged into or logged out of the device that has Data
Guardian installed.
• Content Based Protection - previously Data Classification (Windows)
• Protected Email (Windows) - Relates to files other than protected Office
documents.
• Share (Windows) - Lists events when a user shares one or more files or attaches
an encrypted file to an email.
• Beacon - (protected Office documents) Indicates a device without Data Guardian
installed that tried to access a protected file. These audit events may have limited
data. For example, the location where the file was accessed but without the name
of the user of the device.
• Time stamp - Select the amount of past time for audit events to display - 1, 7, 14, 30, 60, or 90
days.
• More - If you set filters and create a query, you can select the filter options in More to modify
the query. As you select an option, it displays as a menu. Some actions apply to Windows,
Mac, and mobile devices. Some are specific to one or more.
• Action - The default is All. Select one or more check boxes to display specific actions
associated with the payload file. See Action
and the tables below for details and to
determine the operating system.
• Cloud Action - The default is All. Select one or more check boxes to display the
reason for an Action. See Cloud_Encryption_audit events
and the tables below for
details and to determine the operating system.
• Data Guardian Action - The default is All. Select one or more check boxes to display
the reason for an Action. See