Veritas Data Insight User's Guide
- Section I. Introduction
- Section II. Data Insight Workspace
- Navigating the Workspace tab
- Analyzing data using the Workspace views
- Viewing access information for files and folders
- About viewing file or folder summary
- Viewing the overview of a data source
- Managing data custodian for paths
- Viewing the summary of user activity on a file or folder
- Viewing user activity on files or folders
- Viewing file and folder activity
- Viewing CIFS permissions on folders
- Viewing NFS permissions on folders
- Viewing SharePoint permissions for folders
- Viewing Box permissions on folders
- Viewing audit logs for files and folders
- About visualizing collaboration on a share
- Viewing access information for users and user groups
- Viewing the overview of a user
- Viewing the overview of a group
- Managing custodian assignments for users
- Viewing folder activity by users
- Viewing CIFS permissions for users
- Viewing CIFS permissions for user groups
- Viewing NFS permissions for users and user groups
- Viewing SharePoint permissions for users and user groups
- Viewing Box permissions for users and user groups
- Viewing audit logs for users
- Section III. Data Insight reports
- Using Data Insight reports
- About Data Insight reports
- How Data Insight reporting works
- Creating a report
- About Data Insight security reports
- Activity Details report
- Permissions reports
- Inactive Users
- Path Permissions
- Permissions Search report
- About Permissions Query templates
- Creating a Permissions Query Template
- Creating custom rules
- Permissions Query Template actions
- Using Permissions Search report output to remediate permissions
- Entitlement Review
- User/Group Permissions
- Group Change Impact Analysis
- Ownership Reports
- Create/Edit security report options
- Data Insight limitations for Box permissions
- About Data Insight storage reports
- Create/Edit storage report options
- About Data Insight custom reports
- Considerations for importing paths using a CSV file
- Managing reports
- About managing Data Insight reports
- Viewing reports
- Filtering a report
- Editing a report
- About sharing reports
- Copying a report
- Running a report
- Viewing the progress of a report
- Customizing a report output
- Configuring a report to generate a truncated output
- Sending a report by email
- Automatically archiving reports
- Canceling a report run
- Deleting a report
- Considerations for viewing reports
- Organizing reports using labels
- Using Data Insight reports
- Section IV. Remediation
- Configuring remediation workflows
- About remediation workflows
- Prerequisites for configuring remediation workflows
- Configuring Self-Service Portal settings
- About workflow templates
- Managing workflow templates
- Creating a workflow using a template
- Managing workflows
- Auditing workflow paths
- Monitoring the progress of a workflow
- Remediating workflow paths
- Using the Self-Service Portal
- About the Self-Service Portal
- Logging in to the Self-Service Portal
- Using the Self-Service Portal to review user entitlements
- Using the Self-Service Portal to manage Data Loss Prevention (DLP) incidents
- Using the Self-Service Portal to confirm ownership of resources
- Using the Self-Service Portal to classify sensitive data
- Managing data
- About managing data using Enterprise Vault and custom scripts
- Managing data from the Shares list view
- Managing inactive data from the Folder Activity tab
- Managing inactive data by using a report
- Archiving workflow paths using Enterprise Vault
- Using custom scripts to manage data
- Pushing classification tags while archiving files into Enterprise Vault
- About adding tags to files, folders, and shares
- Managing permissions
- Configuring remediation workflows
- Appendix A. Command Line Reference
About the Self-Service Portal
Data Insight enables you to monitor the data on Network Attached Storage (NAS) and helps you to identify the data owner of files and folders based on the access history. It lets you carry out forensics in the form of various pre-canned and custom reports.
Data Insight also lets you manually tag users in your organization as being responsible for the resources in your storage environment. Such users are called custodians and are responsible for remediating these resources.
Data Insight integrates with Data Loss Prevention (DLP) to help security administrators and the information security teams in your organization to monitor and report on access to sensitive information. A Data Insight lookup plug-in retrieves information from the DLP Enforce Server about confidential information on the shares being monitored by Data Insight. DLP creates an incident for every file that violates configured DLP policies. The DLP Network Discover incident report lists such file system shares. The usage information that Data Insight collects automatically feeds into the incident detail of files that violate DLP policies. Data Insight identifies the data owners to notify about these incidents. This method enables users to identify sensitive data along with the responsible users to enable more efficient remediation and data management.
Data Insight also enables you to review permissions on files and folders and remediate excessive permissions. Analyzing the permissions on resources ensures that only users with the business need have access to the data.
Thus, Data Insight supports large-scale business owner-driven remediation processes and workflows. You can create workflows from the Data Insight Management Console, and submit these workflows for further action by selected custodians or configured data owners.
The Self-Service Portal provides you an interface to complete the remediation workflows. When you submit a workflow from the Data Insight console, on the start date of the workflow an email is sent to the custodians of the selected resources. The email includes a link to the Self-Service Portal. The custodians can then do the following tasks on the portal:
Launch the portal using the link in the email, and log in to the portal with their Active Directory credentials.
View the resources that need to be remediated.
Apply configured actions on the resources that are assigned to them.
Submit the requests for execution to the DLP Enforce Server, Enterprise Vault server, or the Data Insight Management Server, depending on the type of workflow request.
The files on which an action is submitted no longer appear on the portal. The summary of the total files awaiting remediation is also updated to show the number of remaining files. You can view the number of submitted files and the files on which an action is pending at the top-right corner of the page.
If you fail to take action on the paths that are submitted for your attention within the stipulated time, the workflow is canceled.
The Self-Service Portal is available beginning Veritas Data Insight version 4.5. You can use the portal for remediating incidents beginning Symantec Data Loss Prevention version 12.5.