Arctera™ Insight Surveillance User Guide

Last Published:
Product(s): Veritas Alta Surveillance (1.0)
  1. Introducing Arctera Insight Surveillance
    1.  
      About Insight Surveillance
    2.  
      Insight Surveillance multi-tier architecture
    3.  
      System requirements
    4.  
      Sampling support for content sources
    5.  
      AI-based label predictions support for efficient review process
    6.  
      Date format support in Insight Surveillance
    7.  
      About Insight Surveillance system security
  2. Getting started
    1.  
      Signing in to Insight Surveillance
    2.  
      Signing out from Insight Surveillance
    3.  
      Launching Arctera Insight Archiving applications
    4.  
      Resetting a forgotten password
  3. Working with dashboard widgets
    1.  
      Understanding the Dashboard page
    2.  
      Viewing status summary of recently reviewed departments
    3.  
      Pinning and unpinning departments to view review status
    4.  
      Changing the order of pinned departments
    5.  
      Viewing the review status summary of escalated items
    6.  
      Viewing a summary of searches and exports
  4. Managing employee groups
    1.  
      Managing employee groups
  5. Managing departments
    1.  
      About departments
    2.  
      Understanding the Departments page
    3.  
      Searching departments
    4.  
      Creating departments
    5.  
      Moving existing departments under other departments
    6.  
      Adding monitored employees and employee groups to departments
    7.  
      Editing monitoring policies
    8.  
      Editing department details and monitoring policy
    9.  
      Managing exception employees
    10.  
      Designating employees as exception employee
    11.  
      Assigning further exception reviewers to an exception employee
    12.  
      Removing exception status
    13.  
      Removing exception reviewers
  6. Managing department users
    1.  
      Assigning users to departments
    2.  
      Removing users from departments
    3.  
      Adding new roles for users
    4.  
      Removing roles
    5. Managing role assignment for a user in departments
      1.  
        Assigning departments and exceptions to specific users
      2.  
        Removing a specific role to users in one or more departments and exceptions
  7. Managing department-level searches
    1.  
      About department-level searches
    2.  
      Guidelines for effective searches
    3.  
      Creating and running department-level searches
    4.  
      Disabling scheduled searches
    5.  
      Using proximity searches
    6.  
      Previewing search results
    7.  
      Accepting search results
    8.  
      Rejecting a search result
    9.  
      Resubmitting a search
  8. Managing department-specific hotword sets
    1.  
      Overview
    2.  
      Creating department-specific hotword sets
    3.  
      Editing department-specific hotwords and hotword sets
    4.  
      Deleting department-specific hotword sets
  9. Managing department-specific labels
    1.  
      Searching department-specific labels, label groups, and single choice groups
    2.  
      Managing department-specific labels
    3.  
      Managing department-specific label groups
    4.  
      Managing department-specific single choice label groups
  10. Managing department-specific trash rules
    1.  
      Overview
    2.  
      Creating department-specific trash rules
    3.  
      Activating department-specific trash rules
    4.  
      Deactivating department-specific trash rules
    5.  
      Propagating department-specific trash rules
    6.  
      Unpropagating department-specific trash rules
  11. Managing department-specific allowlist rules
    1.  
      Overview
    2.  
      Creating department-specific allowlist rules
    3.  
      Editing department-specific allowlist rules
  12. Managing department-specific review comments
    1.  
      About department-level review comments
    2.  
      Adding department-level review comments
    3.  
      Editing department-level review comments
    4.  
      Deleting department-level review comments
    5.  
      Updating order of department-level review comments
  13. Viewing employees associated with departments
    1.  
      Viewing employee association history
  14. Managing users, roles, and permissions
    1.  
      Overview
    2.  
      Predefined user roles and permissions
    3.  
      Adding new roles for users (employees) and employee groups
    4.  
      Editing user roles and permissions
    5.  
      Deleting user roles
    6.  
      Assigning Insight Surveillances to users (employees) and employee groups
    7.  
      Restricting users to use hotwords in searches
    8.  
      Removing a user role
  15. Managing application-level searches
    1.  
      About application-level searches
    2.  
      Viewing existing application-level searches
    3.  
      Creating and running application-level searches
    4.  
      Editing application-level searches
    5.  
      Excluding departments from application searches
    6.  
      Reinstating the excluded department for application searches
  16. Managing application-specific hotword sets
    1.  
      Overview
    2.  
      Creating application-specific hotword sets
    3.  
      Editing application-specific hotwords and hotword sets
    4.  
      Deleting application-specific hotword sets
  17. Managing application-specific labels
    1.  
      Searching application-specific labels, label groups, and single choice groups
    2.  
      Managing application-specific labels
    3.  
      Managing application-specific label groups
    4.  
      Managing application-specific single choice label groups
  18. Managing application-specific trash rules
    1.  
      Overview
    2.  
      Creating application-specific trash rules
    3.  
      Activating application-specific trash rules
    4.  
      Deactivating application-specific trash rules
    5.  
      Propagating application-specific trash rules
    6.  
      Unpropagating application-specific trash rules
  19. Managing application-specific allowlist rules
    1.  
      Overview
    2.  
      Creating application-specific allowlist rules
    3.  
      Editing application-specific allowlist rules
  20. Managing application-specific review comments
    1.  
      About application-level review comments
    2.  
      Adding application-level review comments
    3.  
      Editing application-level review comments
    4.  
      Deleting application-level review comments
    5.  
      Updating order of application-level review comments
  21. Managing data requests
    1.  
      About data request
    2.  
      Creating a new data request
  22. Managing search schedules
    1.  
      Overview
    2.  
      Setting up new search schedules
    3.  
      Setting up one-time search schedules
    4.  
      Example of a one-time search schedule
    5.  
      Setting up recurring search schedules
    6.  
      Example of a recurring search schedule
    7.  
      Editing search schedules
    8.  
      Deleting search schedules
  23. Managing export operations
    1.  
      About exporting items
    2.  
      Performing export runs
  24. Managing reviews
    1.  
      About reviewing with Insight Surveillance
    2.  
      Limitations on reviewing certain types of Skype for Business content
    3.  
      Understanding the Review page
    4.  
      Changing the Preview pane position
    5.  
      Rearranging columns in the item list pane
    6.  
      Filtering the items in the Review pane
    7.  
      Viewing dynamic review item counts on the calendar
    8.  
      Reviewing searched items
    9.  
      Translating email and attachment content for review
    10.  
      Adding or removing text for machine learning
    11.  
      Assigning review status to items
    12.  
      Viewing hotwords highlighting
    13.  
      Viewing hotwords in collaboration message
    14.  
      Viewing tags highlighting
    15.  
      Viewing predicted labels of review items
    16.  
      Viewing the full content in a new window
    17.  
      Adding comments to items
    18.  
      Escalating the review items
    19.  
      Applying labels to items
    20.  
      Viewing history of items
    21.  
      Printing and downloading the items and attachments
    22.  
      Viewing Intelligent Review Details
  25. Working with reports
    1.  
      About Insight Surveillance reports
    2.  
      Predefined reports
    3. Enhanced reporting
      1.  
        Configuring a reporting endpoint
      2.  
        Authentication
      3. Departments API
        1.  
          Departments - List
      4. Users API
        1.  
          Users - List
      5. UserRoles API
        1.  
          UserRoles - List by filters
      6. Roles API
        1.  
          Roles - List
        2.  
          Roles - List by filters
      7. Classification Tags API
        1.  
          Classification Tags - List
      8. Labels API
        1.  
          Labels - List
      9. Searches API
        1.  
          Searches - List
      10. ItemMetrics API
        1.  
          ItemMetrics - List
        2.  
          ItemMetrics - List by filter
      11. ReviewerMapping API
        1.  
          ReviewerMapping - List
      12. MonitoredEmployees API
        1.  
          MonitoredEmployees - List
      13.  
        Evidence Of Review Async API
      14. Evidence of Review API
        1.  
          EvidenceOfReview - List by filter
      15.  
        Item Classification Metrics Async API
      16. Item Classification Metrics API
        1.  
          ItemClassificationMetrics - List by filter
      17.  
        Item Label Metrics Async API
      18. Item Label Metrics API
        1.  
          ItemLabelMetrics - List by filter
      19.  
        Item Archived Metrics Async API
      20. Item Archived Metrics API
        1.  
          ItemArchivedMetrics - List by filter
      21.  
        Report Status API
      22.  
        Supported OData query options
      23.  
        Supported reporting endpoint API filters and their values
      24.  
        Responses
    4. Managing Power BI templates for reporting APIs
      1.  
        Accessing Insight Surveillance reports and datasets through the OData web service
      2.  
        Guidelines for using Insight Surveillance templates with Microsoft Power BI Desktop
      3.  
        TEMPLATE - Departments, Users, Roles, Labels
      4.  
        TEMPLATE - User Roles
      5.  
        TEMPLATE - Item Metrics
      6.  
        TEMPLATE - Reviewer Mapping
      7.  
        TEMPLATE - Searches
      8.  
        TEMPLATE- Item Classification Metrics - Submit report request
      9.  
        TEMPLATE- Item Classification Metrics - View report data
      10.  
        TEMPLATE- Item Archived Metrics - Submit report request
      11.  
        TEMPLATE- Item Archived Metrics - View report data
      12.  
        TEMPLATE- Item Label Metrics - Submit report request
      13.  
        TEMPLATE- Item Label Metrics By Employee - View report data
      14.  
        TEMPLATE- Item Label Metrics By Department - View report data
      15.  
        TEMPLATE- Evidence Of Review - Submit report request
      16.  
        TEMPLATE- Evidence Of Review By Monitored Employee - View report data
      17.  
        TEMPLATE- Evidence Of Review By Department - View report data
      18.  
        TEMPLATE- Evidence Of Review With Item Archived Metrics - Submit report request
      19.  
        TEMPLATE- Evidence Of Review With Item Archived Metrics - View report data
      20.  
        Saving, editing, and refreshing the Power BI reports
  26. Managing Audit Settings
    1.  
      Audit Settings Overview
    2.  
      Editing the Audit Settings
  27. Working with Audit viewer
    1.  
      About Audit viewer
    2.  
      Performing a search for audit records

Creating and running application-level searches

To understand the prerequisites, See About application-level searches.

To create and run an application-level search

  1. In the left navigation pane, click Application.
  2. In the Searches tab, click New Search.

    The Create New Search dialog box appears. If the sections in this dialog box are in the collapsed state, expand them to view the corresponding fields.

  3. In the Search Type section, specify the relevant information in the following fields.

    The New Search dialog box appears. This section identifies the search and specifies when it runs.

    Search In

    Displays the departments in which the search will run. In the case of an application-wide search, by default this value is <All Departments>.

    Based on search

    Select an existing search as the basis on which you can set the criteria for the new search.

    Search Type

    Select the type of search as needed.

    • Select the Scheduled option to specify a period during which the search is to run. Specify the schedule run start date and end date.

    • Select the Guaranteed Sample option to run the search at the selected sampling time, which is 1:00 A.M. by default. Select the Enabled check box to enable the search.

    Name

    Type a name for the search.

    Include items already in review

    Select this check box to specify whether the search results can include the items you previously captured and added to this department's review set. This option does not apply to the items you previously included in the review sets for other departments.

    For an immediate search or scheduled search, you can select this box to ensure that the results include the items that may already be in review from other searches.

    Search Schedule

    Select a required search schedule based on which the search runs at set times or set intervals.

    Schedule run start date

    Select a date on which the search needs to run.

    Schedule run end date

    Select a date on which the search needs to stop running.

  4. In the Sampling section, specify the relevant information in the following fields.

    This section lets you sample the search results and add a random selection of items to the review set.

    Sampling percentage

    Specify the percentage of search results to include in the review set. You can specify fractions, as in 10.25.

    You cannot change the sampling percentage if the owner of the department has locked this setting in the department properties.

    Set minimum items per author

    Specify the minimum number of items per author to include in the review set. If there are no items for an author in the search results, none can be included in the sample.

    Note:

    As the authors can be from outside the selected department, searches may return more results.

    Set absolute item limit

    Specify an upper limit on the total number of search results to add to the review set. This option takes precedence over any values that you set in the Sampling percentage field.

  5. In the Date range section, specify the relevant information in the respective fields.

    This section lets you search for items according to when they were sent or received.

    Specific date range

    Specify the date and time duration to search items that were sent or received during the selected period.

    Today / Yesterday / Last 7 days / Last 14 days / Last 28 days

    The date ranges are relative to when the search runs, which is today in the case of an immediate search.

    You may find these options useful when creating a scheduled, recurrent search that runs once every day, week, two weeks, or four weeks. For example, if the search runs once a week, select Last 7 days to limit the range to the days since the search last ran.

    Since search last ran

    For a scheduled search only, lets you search the new items that have arrived since the last time you ran the search. This option is similar to options such as Today and Yesterday. However, it lets you set an explicit start date for the first run of the search. By default, this option searches from the date of the last run (or the start date for the first search) to the current day minus 1 (that is, up to yesterday).

  6. In the Authors and recipients section, specify the relevant information in the following fields.

    This section targets the departments for the search and the direction of the items to search. Any departments that you have organized into partitions can only search items to and from departments in the same partition.

    Message Route

    Specify the departments you wish to search as well as the direction of the items you wish to search. Search for the items that are to or from the selected departments, and for the items that have traveled between the selected departments and other departments.

    You can search for the items that follow the following message route:

    • Between "the specified department" and

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    • TO "the specified department" from

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    • FROM "the specified department" to

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    Any of / All of

    To search within department tags, select a department. To search within the To/From fields, only select the employees.

    You can expand the department tag to select monitored employees. If there are a large number of employees in the department, you can click the search icon in front of the department tag, which opens a new window where you can search and select monitored employees.

    Use inheritance, automatically include new departments

    Specify whether to apply the search to the subdepartments of the selected departments.

    By default, any new departments that are subdepartments of others automatically inherit any active, recurring searches that are applied to those departments. This is also true of any existing departments that you move under departments that have recurring searches.

    Department tree

    Specify the departments you want to include in the search. Click the arrows to the left of the department names to expand them and view the nested departments.

    Freeform email addresses / domains

    This field is available for all possible message routes. Type one or more email addresses and domains.

    Type each address or domain on a line of its own to search for the items where the From, To, CC, or BCC fields contains any of the addresses or domains. Type all the addresses and domains on a single line to search for items in which they are all present.

    Place the minus sign (-) in front of an address or domain to exclude it from the search. To exclude multiple addresses or domains, type them all on a single line.

    Note:

    You can use Freeform email addresses / domains to search for email addresses associated with the user accounts but now use the discontinued domain.

    To search for previously monitored employees, you should use department internal AND/OR External to organization message route, and then use the Freeform email addresses / domains option to provide email addresses or domains.

  7. In the Search terms section, specify the relevant information in the following fields.

    This section specifies the words or phrases for which the application should search in the subject lines of items and their bodies. By default, when you search for words in both the subject of an item and its content, the application finds those items that meet one or both criteria. However, it is possible to set up the application so that only those items that meet both criteria are found.

    Subject

    Type the keywords or phrases to be searched in the review items either in their subject lines or in the file names of their attachments. Press Enter to separate keywords and phrases from each other.

    Alternatively, click Hotwords to select hotword sets and keywords.

    If the department has a parent department, you can select hotwords/hotword sets from the current department and its parent department and global hotwords/hotword sets. Hotwords/hotword sets from any of the closed parent departments will not be available for selection. The application searches hotwords/hotword sets from both departments and its parent department and global hotwords/hotword sets.

    Note:

    • Use an asterisk (*) wildcard to represent zero or more characters in your search. Use a question mark (?) wildcard to represent any single character. A wildcard search always finds items that match your search criteria and that were archived in Insight Surveillance.

    • Use a minus sign (-) to indicate you want to exclude from the search results any items that contain the following word or phrase.

      For example, the search to find the items that contain either of the words Agent and Agency, but do not contain the word Cost. ("(Agent AND NOT Cost) OR (Agency AND NOT Cost)"):

      Any of: Agent -Cost

      Agency - Cost

    • A search term cannot comprise an excluded word or phrase only. When you specify such words or phrases, you must also specify a positive word or phrase you want to appear in the search results.

    • A search term cannot start with any of the following characters on any line: = + - @. For example, "Agent -Cost" is a valid search term but "-Cost Agent" is not.

    • Insight Surveillance ignores any non-alphanumeric characters in the search term, except for those that have special significance, such as the plus sign, minus sign, and question mark. For example, a search for the term US@100 may find instances not only of US@100 but also of US 100 and US$100. Including non-alphanumeric characters in the search term may therefore return more results than you expect.

    Content

    Specify the keywords or phrases to be searched in the content of review items.

    Alternatively, click Hotwords to select hotword sets and keywords.

  8. In the Attachments section, specify the relevant information in the respective fields.

    This section lets you search for items of a certain size and type or that have the specified retention category.

    Number

    Specify the required number of attachments.

    You can search the items with specific number and type of attachments. The default option, Does not matter, means that the item can have zero or more attachments.

    All following other options require you to type one or two values that specify the required number of attachments:

    • Equals: requires a specific number of attachments.

    • Between: requires the number of attachments messages must have to a value between those to be specified.

    • Less than: requires a number of attachments below the number specified.

    • Greater than: requires any number of attachments greater than the number specified.

    File extensions

    Specify the file name extensions of particular types of attachments for which to search. Separate the extensions with space characters.

    For example, type the following to search for items with HTML or Microsoft Excel file attachments:.htm .xls.

  9. In the Miscellaneous section, specify the relevant information in the respective fields.

    This section lets you search for items of a certain size and type or that have the specified retention category.

    Message size

    Specify the size in kilobytes of each item for which to search, as reported by the message store (Exchange, Domino, and so on). The item size includes the size of any attachments.

    The following options are available:

    • Does not matter: any number from 0 upward can be attached.

    • Equals: requires a specific number of attachments.

    • Between: requires the number of attachments messages must have to a value between those to be specified.

    • Less than: requires a number of attachments below the number specified.

    • Greater than: requires any number of attachments greater than the number specified.

    Message type

    Displays a list of configured and enabled content sources for the customer.

    Select the All content sources check box to consider messages from all types of content sources simultaneously. When this option is selected, other options remain disabled.

    To select specific message type, clear the All content sources check box, and select one or more required options from the content sources available in the list.

    Trash option

    Select the appropriate option to search for items in trash:

    • Ignore trash - does not search for items in the trash.

    • Include trash - searches for items in other specified options along with the items in trash.

    • Trash only - only searches for items in trash.

  10. In the Tags section, specify the relevant information in the respective fields.

    This section lets you search for items according to the tags with which any additional policy management software has classified them.

    Filter

    Select any of the following options to search for the items that match certain classification policies. There are several types of policies:

    • Inclusions only: Select this option to include items that your policy management software has classified for inclusion in the review set that may contain the most serious offenses, such as swearing, racism, or insider trading.

    • Ignore inclusions: Select this option to ignore items that Arctera Insight Classification has classified for inclusion in the review set that may contain the most serious offenses, such as swearing, racism, or insider trading.

    • Exclusions only: Select this option to include spam items and newsletters that your policy management software may classify for exclusion from the review set.

    • Ignore exclusions: Select this option to ignore spam items and newsletters that your policy management software may classify for exclusion from the review set.

    • Categories only: Select this option to include categorized items that exhibit certain characteristics, such as containing Spanish text. This type of policy provides no information on whether an item should be included in or excluded from the review set.

    • Ignore inclusions and exclusions: Select this option to ignore inclusion and exclusion items.

    • Custom: Select this option and type the names of one or more policies. Separate multiple tag names with commas, like this:

      CustomTag1,CustomTag2

    • All: Select this option to include all tags.

    Note:

    Arctera Insight Classification is required to classify items based on their content and metadata. Implementing Insight Classification requires additional charges.

    Name

    Select tag names. Separate multiple tag names with commas, like this:

    CustomTag1,CustomTag2

  11. In the Intelligent Review section, choose options for the learning engine in Insight Surveillance.

    This engine allows Insight Surveillance to search for items intelligently, based on the actions that reviewers have taken on earlier items. For example, after a reviewer has marked a spam message or out-of-office reply as irrelevant then, when Insight Surveillance detects other items that have similar characteristics, it can handle them in the same way.

    Note:

    Searches that use the intelligent review feature may take slightly longer to complete than those that do not use this feature.

    Searches, by default, consider metadata and content of items to determine the relevance. However, if search results contain items that are older than 30 days, only metadata is considered to determine the relevance.

    The options for Learning behavior are as follows:

    None

    Insight Surveillance searches for items in the normal way, without implementing Intelligent Review. This is the default option.

    Search and prioritize

    Insight Surveillance searches for both relevant items and irrelevant items without favoring one over the other. So, if your chosen Sampling percentage value requires that you capture and review 10% of items, Insight Surveillance captures 10% - but a substantial number of the items may be irrelevant.

    With this option, however, Insight Surveillance does give the items a status of either Unreviewed (Irrelevant) or Unreviewed (Relevant) as it adds them to the review set. When you later review the items in the Review pane, you can filter them by their Unreviewed status to distinguish between the relevant and irrelevant items.

    Search and then sample ONLY relevant content

    Insight Surveillance searches across all the items and captures the relevant ones only, until it has captured the required percentage. So, if your chosen Sampling percentage value requires that you capture and review 10% of items, Insight Surveillance captures 10% - all of them considered to be relevant.

    If there are too few relevant items to fulfil the chosen sampling percentage, Insight Surveillance does not supplement them with irrelevant items. This is an important difference between this option and the equivalent option, Sample exact percentage of ONLY relevant content, in the Department Properties pane.

  12. Click Save.

Note:

When more than 500 departments are selected in an application search, the search gets disabled for performance reason. Navigate to Application > Searches > Edit to confirm departments, and then enable the search.