Skip to main content

Hello, 

 

I have deployed and activated several TSPs from TSP Accelerator. Some of them works with no issue, I can see that I have received email notification when rule was executed: 

For example for Monitor Internal Logins that Bypass SSO, Detect Privilege Escalation. 

However, for the following TSPs, I don't receive email notifications:  

Detect Login As Events - to test this rule I simply login as another user. 

Detect High Risk Data in List View, Detect High Risk Data in Report Export - I have email field configured for Account and Email in the Data Sensitivity Level as Confidential. And Confidential is marked as High-Risk in Data Sensitivity Picklist Values. To test it I create list view or Report (and do export) with Email field. 

Detect Report Exports by Unapproved Profiles - I have two profiles configured in Approved Profiles for Report Export metadata. I login as user with profile that is not in the list and create report and do export. 

 

I checked the configuration, metadata, confidential data settings, rules are activated, email notification configured to be sent to the expected user. 

 

I would appreciate any help to understand why the email notifications are not sent. 

 

Thank you

답변 4개
  1. 7월 14일 오후 6:18

    As a troubleshooting step, you may query the Event Log Object (ex. LoginAsEvent, ApiEvent, etc) returning the PolicyOutcome and PolicyId (or traverse to the policy object itself, ex Policy.MasterLabel) to determine if the policy is being evaluated.  

    And as another step, you may review the policies in the

    open source repository to understand the logic and determine what may be causing the results in your org. 

0/9000