<h2>Configure advanced settings for Data Loss Prevention Incident Response</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="task" /><meta name="DC.title" content="Configure advanced settings for Data Loss Prevention Incident Response" /><meta name="abstract" content="Configure the advanced settings so that you can determine the fields on the Incident for identifying the end users, among other capabilities." /><meta name="description" content="Configure the advanced settings so that you can determine the fields on the Incident for identifying the end users, among other capabilities." /><meta name="DC.subject" content="Data Loss Prevention" /><meta name="keywords" content="Data Loss Prevention" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/concept/data-loss-prevention-administration.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-data-loss-prevention.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-enduser-lookup-rules.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/create-assignment-rules.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-incident-consolidation-rules-to-consolidate-your-dlp-incidents.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/setup-response-due-date-rules.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-approval-rules.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/create-and-manage-user-instructions-template-for-dlp-incidents.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/create-and-manage-email-templates.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/sla-records.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/dlp-sla-definitions.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/create-and-manage-assessments-for-dlp-incidents.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-end-user-action.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-age-chart.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-delegation.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/repeat-offender-identification-rules.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/configure-custom-states-dlp.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/create-custom-fields-dlp.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/reference/dlp-sla-def-properties.html" /><meta name="DC.relation" scheme="URI" content="../../../product/dlp-microsoft/concept/configure-microsoft-dlp-integration-run-process.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/concept/dlp-incident-access-restrictions.html" /><meta name="DC.relation" scheme="URI" content="../../../product/data-loss-prevention/task/dlp-archiving-rule.html" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2024-08-01" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="configure-advanced-settings-dlp" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Configure advanced settings for Data Loss Prevention Incident Response</title></head><body id="configure-advanced-settings-dlp"> <h1 class="title topictitle1" id="ariaid-title1">Configure advanced settings for <span class="ph">Data Loss Prevention Incident Response</span></h1> <div class="body taskbody"><p class="shortdesc">Configure the advanced settings so that you can determine the fields on the Incident for identifying the end users, among other capabilities.</p> <div class="section prereq p"> <div class="p">Role required:<ul class="ul" id="configure-advanced-settings-dlp__ul_i4v_zgh_h5b"><li class="li">sn_dlir.admin - Create, edit, and delete.</li><li class="li">sn_dlir.analyst and sn_dlir.analyst_read - View (read-only).</li></ul> </div> </div> <div class="section context" id="configure-advanced-settings-dlp__context_txx_kl5_vsb"> <div class="p">Configuring advanced settings on the <span class="ph">Data Loss Prevention Incident Response</span> is optional. Some advanced settings include the following:<ul class="ul" id="configure-advanced-settings-dlp__ul_ifp_hlb_ftb"><li class="li">Define the maximum number of incidents that can be sent in a digest email.</li><li class="li">Enable quick mode to send emails faster.</li><li class="li">Determine the log verbosity of the application.</li></ul> </div> </div> <ol class="ol steps"><li class="li step stepexpand"> <span class="ph cmd">Navigate to <span class="ph menucascade"><span class="ph uicontrol">All</span> > <span class="ph uicontrol">DLP Administration</span> > <span class="ph uicontrol">Advanced Settings</span></span>.</span> </li><li class="li step stepexpand"> <span class="ph cmd">On the form, fill in the fields.</span> <div class="itemgroup info"> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="configure-advanced-settings-dlp__table_dzh_lm5_vsb" class="table" frame="border" border="1" rules="all"><caption><span class="tablecap"><span class="table--title-label">Table 1. </span>Advanced Settings form</span></caption><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><thead class="thead" style="text-align:left;"><tr class="row"><th class="entry cellrowborder" style="vertical-align:top;" id="d203431e118">Field</th><th class="entry cellrowborder" style="vertical-align:top;" id="d203431e121">Description</th></tr></thead><tbody class="tbody"><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Should the sensitive data which caused the violation be displayed on the incident?</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to choose whether you want to display the sensitive data that caused the violation on the DLP incident.<p class="p">By default, this option is enabled.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Should the sensitive data which caused the violation be displayed on the child incidents as well?</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to choose whether you want to display the sensitive data that caused the violation on the DLP child incident as well.<p class="p">By default, this option is turned off.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">List of fields on the incident that are used to identify the end user</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">The list of fields on the incident of the Assignment Rule module that are used to identify the end user. You can also specify your own custom attributes to identify the end user.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Maximum number of incidents in a digest email</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">The maximum number of incidents that can be sent in a digest email.<p class="p">By default, the value is 100.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Repeat offense maximum duration (in days)</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">The maximum duration to identify a repeat offender.<p class="p">By default, the value is 90 days.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Quick mode to send emails</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to validate emails and identify issues. You can perform the validation by enabling the <span class="ph uicontrol">Yes</span> option.<p class="p">By default, this option is enabled.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">This property is used to set the log verbosity of the application</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">The log verbosity level of the application, meaning the name of the type of information. You can also update the value to the following options:<ul class="ul" id="configure-advanced-settings-dlp__ul_ucl_sp5_vsb"><li class="li"><span class="ph uicontrol">error</span></li><li class="li"><span class="ph uicontrol">warn</span></li><li class="li"><span class="ph uicontrol">info</span></li><li class="li"><span class="ph uicontrol">debug</span></li></ul> <p class="p">By default, the value is <span class="ph uicontrol">info</span>.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Exclude cloned and child incidents from reports</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to exclude the cloned and child incidents from the reports.<p class="p">By default, this option is <span class="ph uicontrol">Yes</span>.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Day(s) to wait for deleting match content on cloud storage after incident gets closed</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to choose the number of wait days to clean up the match content of those incidents which are inactive for a specific time duration.<p class="p">By default, the value is 90. After 90 days if DLP incident is inactive then the match content will be cleaned up from the cloud storage.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Assign Incident to DLP Analyst group after last escalation level</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Select this checkbox to assign the incident to the analyst after the last escalation level.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Allow users to access incidents post escalation</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Select this check box to allow the assigned users to access the incident(s) after the escalation.<p class="p">When you select this option, all the users that were added to the escalation chain list will then be able to access the incident(s).</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Allow analyst to edit completed assessment</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Select this check box to allow the analyst to edit the completed assessment.<p class="p">When you select this option, the analysts can edit the Assessments, when unselected you can view the assessments in the Read-Only mode.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 "> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 "> </td></tr><tr class="row"><td class="entry cellrowborder" colspan="2" style="vertical-align:top;" headers="d203431e118 d203431e121 ">Evidence Files Preview Properties</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Enabling this system property activates the evidence file preview feature in the DLP analyst workspace.<p class="p">sn_dlir.enable_evidence_file_preview</p> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to choose whether you want to preview the evidence files directly in the workspace.<p class="p">By default, this option is <span class="ph uicontrol">Yes</span>.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">This will allow DLP users to download the previewed evidence files. Once this property is enabled, users will see a download button in the document viewer to download the evidence file.<p class="p">sn_dlir.enable_download in_preview</p> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to choose whether you want to display the download button in the document viewer, which will allow you to download the previewed evidence files.<p class="p">By default, this option is <span class="ph uicontrol">Yes</span>.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">This property determines the duration for which files will be temporarily retained for evidence file preview purposes. (in minutes)<p class="p">sn_dlir.preview_temp_files_cleanup_interval</p> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">The maximum duration for which files are temporarily stored for evidence file preview.<p class="p">By default, the value is 10. After 10 minutes if DLP incident is inactive then the evidence file will be cleaned up from the analyst workspace.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">Enabling this property will extend the cleanup interval if evidence files are in use. This will allow the system to extend the expiry time of evidence files based on the value set in the system property "sn_dlir.preview_temp_files_cleanup_interval".<p class="p">sn_dlir.extend_cleanup_interval_on_usage</p> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to extend the time before evidence files are deleted if they are being used.<p class="p">By default, this option is <span class="ph uicontrol">Yes</span>.</p> </td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e118 ">The maximum duration to extend the cleanup interval of evidence files (in minutes).<p class="p">sn_dlir.max_extension_duration_for_cleanup</p> </td><td class="entry cellrowborder" style="vertical-align:top;" headers="d203431e121 ">Option to select how long, in minutes, the system will keep your evidence files before cleaning them up.<p class="p">By default, the value is 60.</p> </td></tr></tbody></table> </div> </div> </li><li class="li step stepexpand"> <span class="ph cmd">Click <span class="ph uicontrol">Save</span>.</span> </li></ol> </div> <div class="related-links"> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="../../../product/data-loss-prevention/concept/data-loss-prevention-administration.html" title="You can set up and assign rules, configure due date rules, use email templates, configure end-user response actions, and much more to manage the Data Loss Prevention Incident Response (DLP IR) incidents on the ServiceNow AI Platform.">DLP Incident Response Administration</a></div> </div> <div class="linklist relinfo relconcepts"><strong>Related concepts</strong><br /> <ul class="linklist"><li class="linklist"><a class="link" href="../../../product/dlp-microsoft/concept/configure-microsoft-dlp-integration-run-process.html" title="Track and monitor the ongoing ingestion process. The integration run processes contains the statistics on how much the data was processed and the integration status.">Monitor Microsoft DLP Integration Run process</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/concept/dlp-incident-access-restrictions.html" title="Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.">DLP Incident Access Restrictions</a></li></ul></div> <div class="linklist relinfo reltasks"><strong>Related tasks</strong><br /> <ul class="linklist"><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-data-loss-prevention.html" title="Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.">DLP default configuration settings</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-enduser-lookup-rules.html" title="You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.">Configure end user lookup rules</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/create-assignment-rules.html" title="Create and activate the assignment rules. Then, assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.">Create an assignment rule for your Data Loss Prevention Incident Response incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-incident-consolidation-rules-to-consolidate-your-dlp-incidents.html" title="Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.">Create incident consolidation rules</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/setup-response-due-date-rules.html" title="Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.">Set up the response due date rules for your DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-approval-rules.html" title="Set up approval rules to take approval from various levels of approver users whenever an advanced type of response option is selected.">Configure Approval Rules</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/create-and-manage-user-instructions-template-for-dlp-incidents.html" title="Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.">Create and manage user instructions template for DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/create-and-manage-email-templates.html" title="Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.">Create and manage email templates for your DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/sla-records.html" title="Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.">Create a Data Loss Prevention Incident Response SLA trigger</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/dlp-sla-definitions.html" title="Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.">Create a Data Loss Prevention Incident Response SLA definition</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/create-and-manage-assessments-for-dlp-incidents.html" title="Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.">Create and manage assessments for DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-end-user-action.html" title="Set up the incident response option rules that end user or analyst can use while responding to an incident.">Set up incident response option rules for your DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-age-chart.html" title="Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.">Configure the age chart for your DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-delegation.html" title="Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.">Configure how end-user actions are delegated</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/repeat-offender-identification-rules.html" title="Configure the repeat offender identification rules to identify users who repeat the same issue multiple times.">Configure repeat offender identification rules</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/configure-custom-states-dlp.html" title="Create and configure your own custom states for the DLP IR incidents.">Create custom states for your DLP incidents</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/create-custom-fields-dlp.html" title="Create your Additional Incident Data Fields for the DLP incidents. You can create different types of Additional Incident Data Fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.">Create Additional Incident Data Fields</a></li><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/task/dlp-archiving-rule.html" title="The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.">DLP Incidents Archival</a></li></ul></div> <div class="linklist relinfo relref"><strong>Related reference</strong><br /> <ul class="linklist"><li class="linklist"><a class="link" href="../../../product/data-loss-prevention/reference/dlp-sla-def-properties.html" title="Field descriptions for the DLP SLA Definition form used to create an SLA record.">DLP SLA Definition form</a></li></ul></div> </div></body></html></div>