Reference Guide
Dell Security Center v10.2.7 AdminHelp
61
File Name
File Path
File Key ID
File Size
To search for a specific file, use the file key ID.
Note: When both .xen and protected Office files exist in Mac or mobile or Windows (v2.3 and earlier),
parameters may differ for each audit event but are the same within the event. For example, the data
may differ for sl_xen_file and sl_protected_file, but the data for each Cloud Encryption .xen file event
is the same.
Note: For web portal and CASB, no File Path exists.
Client Type
Indicates whether the client is internal or external. For Windows and Mac, the only option is internal.
Action
The action associated with the payload file. See
Protected_Office_Document_or_Basic_File_Protection_audit_events. For Mac or mobile, see also
Cloud_Encryption_audit events.
Version
For internal Dell use only.
Client
For internal Dell use only. (Windows and Mac)
Column options for Protected Office only
Audit Event - Column options
Description
Data Guardian Action
If a service acts on a protected Office file, for example, modifying or deleting a file, the Data Guardian
Action column lists the reason. See
Protected_Office_Document_or_Basic_File_Protection_audit_events.
Column options related to Embargo:
From
To
From - The time that an external user can start viewing a protected file.
To - The time that an external user can no longer view a protected file.
See also Column_options_for_all_audit_events.
Protected Office Document or Basic File Protection audit events (Windows, Mac, mobile, web portal,
CASB)
This table lists audit events that apply to Office documents or other files entered in Basic File Protection:
• For Windows and Mac, audit events apply to Opt-in or Force Protected modes.
• Mobile has Opt-in mode only.
• Protected Office document audit events do not contain the Cloud Name or Cloud Action events
since protected Office documents can move to a cloud storage provider outside of the bounds
of Data Guardian. Those display for XEN audit events under Cloud_Encryption
.
• Basic File Protection events for Windows (excluding any .xen file extensions)
Actions
for
audit
events
Data Guardian
Action and
Description
Windows
Mac
M
obile
device
Web
portal
CASB
Created
New
Opt-in mode - logs an event when a
user selects Save As Protected and
an Office document is protected.
Force-Protected mode - logs events
when Data Guardian performs a
sweep and creates protected Office
documents.
●
●
●
●
●
Accessed
Open
A user opened a protected Office
document.
●
●
●
●
●
Modified
Swept
For Windows, when Force Protected
is enabled, provides data about files
●
●