Office 365 Reports - Missing Data

MVP

I'm working on a DLP POC for a company.  We've been able to get DLP Policy rules created for the things they want to track.  They are receiving Incident Reports on a regular basis since we turned on the POC.  The problem is with reporting.  We're seeing several issues with the reporting.

  1. In the Security and Compliance Center dashboard report there are several DLP rules and sensitive information type entries that show up as GUID's rather than text.  When we export the XML for the definitions the GUID's can be matched to specific rules that have localized names supplied.  Not sure why the localized names are only showing for some rules and SI's and not for others.
  2. We show hits in the reports that haven't generated an Incident Report email.
  3. The number of entries in the UI dashboard doesn't match the number of lines in the exported report for the same time frame.  There seem to be duplicate entries in the exported report.  This is made more difficult to explain since the exported report doesn't include the Rules column from the dashboard.  Since the same SI types are often used in multiple rules some of these duplications could be multiple different Rules.  But there are more duplicates than there are rules for the same item in the dashboard report.
  4. As I said in #3 the exported report doesn't include the same set of columns that the dashboard report does.
  5. We also tried to export the report the old way from the Exchange Admin Center using Get-DlpDetailReport .  The number of items in this report also doesn't match the other reports for the same time frame.

Anyone have any ideas on this?  Are we doing something wrong?  Or are the reports this buggy?  Can anyone point me at some detailed documentation that will help explain what we are seeing in these reports.  Anyone from Microsoft, are you aware of these issues?

 

All help would be appreciated.

1 Reply

@Paul Stork  

hey Paul what is the chance you got an answer to this 5 years later?

I am facing a similar issue  - we are trying to get DLP reporting to work via schedule/request and keep getting no results - but yet I can export the results manually.

 

all our perms seem correct - 

I have a ticket open with MS but they seem a bit lost as well