Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here

Skyhigh Security

Salesforce Policy Incidents

The Policy Incidents page is a central repository of all incidents that have violated Policies. All Services are consolidated on this page, or you can choose to view the violations occurring in just Salesforce Service. When you upload files to Salesforce as an attachment, then the Skyhigh CASB DLP Policy scans the uploaded files for malware.

If malware is detected, Skyhigh CASB generates an incident. If an email notification is configured, then you receive a malware alert email. You can see the details of the malware in the email.

You can upload more than one file for each service request. To identify the malware in the files, you need to configure the Item ID in Skyhigh CASB. The Item ID is the File ID in Salesforce and it identifies a specific file uploaded in Salesforce.

Find the page at Incidents > Policy Incidents. For generic information, see Policy Incidents Page.

Configure Item ID in Skyhigh CASB

To view the attachments in Salesforce, configure the Item ID in Skyhigh CASB:

  1. Go to Incidents > Policy Incidents.
  2. Under Service Name, select the Salesforce.
  3. Under Actions > Settings, click Edit Table Columns.
  4. Select the Item Id and click Save Table Settings.
    clipboard_e4e308398778b2fadb9b2b3fb94ad50cb.png
  5. The Item Id column is added to the Policy Incident table.
    clipboard_e7fe1250dbd568bdb1d00e6d7dfd65cb8.png
  6. To view the required file or attachment in Salesforce, copy the Item Id and paste into the browser after the Salesforce URL. Construct the URL as shown:
    https://<Salesforce URL> 00P0o00002E6Ui7EAF
    clipboard_ef7368378b4732d121fd2aa1e050ec16a.png

To view Salesforce attachments:

  1. Click the incident in the table to see the Cloud Card for details. 
    clipboard_e8cc0bf71f98370ad8dea59d2bad5f8bb.png
    Here, Path refers to the parent object. Using the parent object, you can view the Salesforce attachments.
  2. Copy the Path and paste into the browser after the Salesforce URL. Construct the URL as shown:
    https://<Salesforce URL> 0010o00002kZ0msAAC.
    clipboard_ee278f125da21ae0b68839937e4854c61.png
  3. To view attachments under the parent object, go to Notes & Attachments.
    clipboard_eab1860fe64207619f26c5ff2f4457021.png

Configure Item ID in Email Template

To receive malware details through email notification, configure the Item ID in the Email Template:

  1. Go to Policy > Policy Settings > Email Templates
    clipboard_e4eb5bf1995289874c66d0f4e87e3c617.png
  2. Select the Category as Data Loss Prevention and Type as Send Email Notification To and click the Email Notification from the table.
  3. Under Variables, select Item ID.
  4. Under Email Body, enter the text of the body to configure the email notification and use the formatting tools to style the text as shown.
    clipboard_e2f2dc9b37f2d7b45df57db737d05f801.png

NOTE: You may also click Restore Default to remove your changes. 

  1. Click Save.
    Now, the malware details are shared as an email notification in the configured format.
    clipboard_ee5e162d46a8a59c51bf3b4db69244efd.png
  • Was this article helpful?