How-To Guides for Data Security for Dell
Introduction
This page answers common "how do I..." questions for Data Security, organized by area. Each question expands into a short answer with a link to the full guide for complete steps. If you don't find your question here, see Troubleshooting or Use Cases for broader scenarios.
Ransomware Defense
How to configure your threat detection for ransomware defense?
Ransomware Defender ships with all threat detectors enabled by default, covering behavioral, extension-based, and honeypot detection categories. Individual detectors can be disabled in Detection Controls → Settings → Threat Detectors if they generate sustained false positives, and the overall response mode (Monitor, Enforcement, or Critical) is set in Detection Controls → Settings → Response Settings — start in Monitor mode for one to two weeks before switching to Enforcement.
How to manage false positives?
Data Security provides four complementary tools for managing false positives — Learned Thresholds, Application Fingerprinting, Monitor Only, and the Ignored List — each with a different scope and precision. The recommended approach layers them: use Learned Thresholds and Application Fingerprinting for ongoing tuning, Monitor Only for new or unknown activity where you still want visibility, and reserve the Ignored List as a last resort for confirmed low-risk paths — never for paths containing sensitive data, where you still need visibility. See the questions below for each individual tool.
How does the application fingerprinting work?
Application Fingerprinting is a machine-learning service built into the Eyeglass appliance that compares each new suspicious event's behavioral characteristics against a database of known-safe application patterns using vector similarity search. If the similarity score exceeds the configured confidence threshold, the event enters Threat Assessment and, once its timer expires, is automatically suppressed and archived as Known Behavior with no lockout or alert.
How do you manage the ignore list and when to use it?
The Ignored List excludes specific paths, users, or source IPs from ransomware detection entirely — matching audit events are dropped before processing, so no Signal Strength accumulates and no event is ever raised. Use only as a last resort, for genuinely non-critical data or fully isolated automation accounts where the operational cost of false positives can't be managed any other way. Never use it for paths containing sensitive data — use Monitor Only instead, so you keep visibility.
How do you manage the monitor list and when to use it?
The Monitor Only list logs and processes activity for specified paths or users, raising any resulting event in Monitor mode — visible on the Threat Detections page, snapshots still taken, no automatic lockout — rather than generating no events at all. This is unlike the Ignored List, which drops matching events before they're processed at all. It's best used during initial deployment, for trusted service accounts, or for any activity you want full audit visibility into before deciding whether to fully ignore or fully enforce it.
How do you manage suspicious extensions?
The Suspicious Extensions tab lists the file extensions that feed the Suspicious Extension threat detector; the master list is maintained and updated automatically by Superna. You can disable an extension that's generating sustained false positives, re-enable one, or add a custom extension — but each disabled extension is a gap in ransomware coverage, so only disable one for a specific, documented reason.
How to review an event and what are the possible actions?
Each event on the Threat Detections page has an Investigate button plus a three-dot Actions menu, grouped into three families — Snapshots, User Lockout, and Event Processing — covering actions like Create Snapshot, Restore User Access, Lockout Now, Mark as Recovered, Archive as False Positive, and Comment, with availability depending on the event's current state. Start your review in the event's detail panel, which shows the triggering threat categories, Signal Strength breakdown, and top file operations, then use Investigate & Recover for the full file-level detail.
How to close an event?
Click Take an Action → Close Event to open the Close Event wizard, then choose one of the manually-selectable closing states — False Positive, Close as Threat, or Unexpected but Not a Threat. (Two additional states, Unresolved and Known Behavior, are applied automatically by the system and aren't options here — see the full Closing event states reference.) Only Close as Threat records a Threat Confirmed outcome; False Positive additionally prompts you to select a learning scope (user, path, group, or all users) so the system can suppress similar events going forward.
How to manage advanced settings (Threat Detectors, severity settings adjustments)?
The precise Signal Strength thresholds, time intervals, and event upgrade criteria for each severity level — split into Single Vector and Dual Vector tracks — are configured in Detection Controls → Settings → Advanced Severity Levels, with a Reset to Default button available to restore factory values. Do not modify these values without guidance from Superna Support, since incorrect configuration can cause missed detections or excessive false positives. To disable an individual detector entirely, see Threat detector types.
A per-detector "Monitor" mode, distinct from disabling a detector, does not appear to be a real, separate setting — searching the legacy portal's dedicated Monitor Mode documentation confirms "Monitor mode" there refers only to the path/user/IP-based Monitor Only list (alert and snapshot without lockout for specific paths, users, or source IPs) and the overall Monitor/Enforcement/Critical response mode covered above — not a per-detector toggle. If a genuinely separate per-detector Monitor mode exists in the current UI, it was not found in either approved source.
Active Auditor
How to configure a trigger?
From Detection Controls → Active Auditor, click + Create Trigger and choose one of three trigger types — Mass Delete, Data Loss Prevention, or Custom Trigger. Mass Delete and Data Loss Prevention are a two-step flow: Choose Trigger, then Basic Configuration (path, thresholds, and interval). Custom Trigger is a four-step flow — Choose Trigger, Basic Configuration, Audit Criteria (the AND/OR rule builder), and Advanced Settings — before confirming to save. Each trigger type has a recommended starting point documented in the full guide, for example 1,000 files per minute for Mass Delete.
How to review an event and take an action?
Active Auditor events appear on the Threat Detections page alongside Ransomware Defender events and share the same event states, detail panel, and Actions menu — including Acknowledge, Lockout Now, Stop Lockout Timer, and Restore User Access. Review the event detail panel for the affected user, Signal Strength breakdown by trigger, and the Top Events file operation chart before taking action.
How to close an event?
Active Auditor events are closed the same way as Ransomware Defender events: Take an Action → Close Event opens the Close Event wizard, where you select False Positive, Close as Threat, or Unexpected but Not a Threat. See "How to close an event?" under Ransomware Defense above for the full classification breakdown.
Data Auditing
How to create a new query?
Click + Create Query on the Queries & Reports tab, select Create Custom Query, enter a Query Name (letters and numbers only) and configure filters for User Name, Path, Event Type, Extension, Time Range, and Max Results, then click Save & Run. Always use the narrowest path and time range that covers your investigation to keep query times manageable.
How to review a report?
Every report run appears in the All Reports panel with its status (Queued, Running, Success, Failed, or Canceled), start time, run type, record count, and duration, and can be filtered by status, report type, or run type. Click the three-dot menu on any completed report row for Download (CSV) or Delete — there is no report viewer in this product; CSV is the only way to review results.
How do I create a report from a built-in query?
Click a query under Built-in Queries in the left panel to load its pre-configured settings, then click Save & Run — you can adjust filters like time range and path first, but you can't save changes back to the built-in query itself. The built-in queries are Stale User Access, User Access, and Employee Exit.
How to use "Where did my folder go?"
Select a cluster and path, set a time frame, choose whether you're searching for Folders or Files/Objects, and optionally check Show Deleted Items, then click Search. Results are capped at 5,000 entries — narrow the time frame or path if you hit that limit — and can be exported using Download CSV.
How to use a Wiretap?
In the Wiretap Configuration panel, select the path to monitor and optionally filter by user, file extensions, or event types, then click Start Wiretap to begin streaming live file system events. WireTap only shows events from the moment the stream starts — use Queries & Reports to search historical activity — and configurations can be saved for reuse.
How to use Bulk Ingest?
After completing the one-time NFS ingestion setup on your ECA cluster, select the cluster, set a Start Date and a Search Previous window, and click Load Files to find available backup audit files, then select the files you want and confirm to start the job. Bulk Ingest is limited to a specific targeted date, a 3-day file window, and a maximum of 20 files per job, and should be scheduled during off-peak hours since it runs at lower priority than live audit processing.
Integrations
How to review available integrations?
The Integrations page provides a searchable grid of all supported integrations — use the search field to find a specific SIEM, SOAR, EDR, or ticketing platform. Each integration in the grid links to its own dedicated setup guide with vendor-specific configuration details.
How to configure a webhook?
In the Data Security web interface, navigate to Integrations → Webhooks and click + Add Webhook. Enter a name, the target URL, and the application type, then click Next to configure the event filter (Define Triggers) and the request headers (Configure Headers, including Content-Type: application/json and any authentication headers your receiving system requires), and click Create. Filter to Critical and Major severities and to lifecycle states that represent an actual containment decision, rather than forwarding every event.
How to configure an integration?
Each supported integration has its own dedicated setup guide with vendor-specific configuration steps — browse or search the Integrations page to find the platform you want to connect, then follow that guide. Most integrations are built on the underlying Data Security event webhook mechanism, so the Webhook Configuration page is useful background before configuring a specific vendor integration. As a worked example, see the Splunk SOAR On-Prem guide linked below — it walks through the full process, from creating a Python virtual environment on the Eyeglass appliance to customizing and testing the integration script.
See also
- Use Cases — Step-by-step response procedures and broader scenarios.
- Troubleshooting — Diagnose and resolve ECA, agent, and Threat Hunting issues.
- Threat Detection and Severity Settings — Detector types, severity levels, and enforcement modes.
- Detection Controls and False Positive Management — Active Auditor, Application Fingerprinting, Ignored List, and Monitor Only.
- Data Auditing — Queries & Reports, Where Did My Folder Go?, WireTap, and Bulk Ingest.
- Integrations — Browse supported SIEM/SOAR/EDR integrations.