Hello,
I have applied DLP policy for passport and swiftcode, both rules are working but facing problem with incident report.
According to DLP, when any rule will be detected then a incident report will be generated and moderator will receive one rule detected email against that rule. But in my organization, my moderator is receiving multiple email against one rule. As example, if a user sends an email (DLP policy matched email) to 5 users the moderator gets 5 incident reports instead of one .
Thanks,
Aparna