๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Google Workspace Rules & DLP

See every time a Google Workspace data loss prevention (DLP) rule or activity rule fired, in one read-only record you can filter and export.

Where to find it
Google Workspace โ€บ Rules & DLP
Who can use it
Anyone who can see the page
Plan
Cloud monitoring (Microsoft 365 / Google Workspace)
For
Everyone

What the page is for

Google does not let outside tools read how DLP rules are configured, but it does record when they trigger. This page collects that record so you can show an auditor what your rules actually caught: which rule fired, for which user and file, in which app, and what action Google took.

The DLP Assessment section combines DLP rule firings with DLP-related alerts from Google's Alert Center. The Rules Activity section shows the full rules log, including both DLP rules and admin activity or automation rules. Both read from your connected Google Workspace and cover the last 90 days by default.

Nothing on this page changes your Google settings.

What you see

The Google Workspace Rules & DLP page, with the summary tiles, dlp assessment, rules activity filters and rules activity numbered 1 to 4.
The Google Workspace Rules & DLP page. Numbers match the list below.
  1. Summary tiles: Rule Events, DLP Firings, Activity Rules, High Severity, Alerted and Distinct Rules. Click a tile to filter Rules Activity; click it again to clear.
  2. DLP Assessment: DLP firings and alerts with Time (UTC), Source (Rule or Alert), Severity, Rule / Alert, App, User, Resource and Actions / Detectors, an item count and Export.
  3. Rules Activity filters: Search (rule, user, resource), Type (DLP or Activity), Severity, Application, Window (30, 90, 180 or 365 days) and a reset button.
  4. Rules Activity: every rule event with Time (UTC), Type, Severity, Rule, App, User, Resource, Actions / Detectors and Alert, an event count and Export.

How to review DLP firings

  1. Look at DLP Assessment. The newest items are at the top.
  2. Check Actions / Detectors to see what Google detected (for example, a credit card number) and what it did.
  3. Click Export in that section to download the list as a CSV file.

How to find high-severity rule events

  1. Click the High Severity tile, or set Severity to High.
  2. Narrow further with Application or Search.

How to change the time window

  1. Choose 30 days, 90 days, 180 days or 365 days in Window.
  2. The page reloads both sections for that period.

How to see only events that raised an alert

  1. Click the Alerted tile.
  2. Rows with an alert show a bell badge in the Alert column.

How to export rule activity

  1. Click Export in the Rules Activity header to download a CSV file.

Tips

  • Severity badges: red HIGH, amber MEDIUM, grey LOW. Events without a severity are shown as medium.
  • Sort Rules Activity by time by clicking Time (UTC).
  • Times on this page are in UTC.
  • Each table shows the first 1,000 rows. Use filters or a shorter window for large tenants.

Troubleshooting

  • "This domain's Google Workspace edition does not include DLP." DLP rules are only available on Enterprise, Frontline, Education and Enterprise Essentials Plus editions. An empty DLP list is expected. Activity rules still appear under Rules Activity.
  • "No rule firings recorded in this window." Either no DLP or activity rules are set up in Google, or none triggered. Try a longer Window.
  • "Rules & DLP data not available yet." Lavawall has not collected rules data for this tenant yet. It fills in after the next Google Workspace sync.
  • "No rule events match." Your filters exclude everything. Click the reset button.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.