Veritas™ Surveillance User Guide

Last Published:
Product(s): Veritas Alta Surveillance (1.0)
  1. Introducing Veritas Surveillance
    1.  
      About Veritas Surveillance
    2.  
      Key features of Veritas Surveillance
    3.  
      Feature comparison: Compliance Accelerator desktop client Vs Veritas Surveillance web client
    4.  
      Sampling support for content sources
    5.  
      About Veritas Surveillance system security
    6.  
      Veritas Surveillance multi-tier architecture
    7.  
      System requirements
  2. Getting started
    1.  
      Signing in to Veritas Surveillance
    2.  
      Signing out from Veritas Surveillance
  3. Working with dashboard widgets
    1.  
      Understanding the Dashboard page
    2.  
      Viewing status summary of recently reviewed departments
    3.  
      Pinning and unpinning departments to view review status
    4.  
      Changing the order of pinned departments
    5.  
      Viewing the review status summary of escalated items
    6.  
      Viewing a summary of searches and exports
  4. Managing employees and employee groups
    1.  
      About employees and employee groups
    2.  
      Creating employee profiles
    3.  
      Editing employee profile details
    4.  
      Creating employee groups
    5.  
      Editing employee group details
  5. Managing departments
    1.  
      About departments
    2.  
      Understanding the Departments page
    3.  
      Searching departments
    4.  
      Creating departments
    5.  
      Moving existing departments under other departments
    6.  
      Adding monitored employees and employee groups to departments
    7.  
      Editing monitoring policies
    8.  
      Editing department details and monitoring policy
    9.  
      Managing exception employees
    10.  
      Designating employees as exception employee
    11.  
      Assigning further exception reviewers to an exception employee
    12.  
      Removing exception status
    13.  
      Removing exception reviewers
    14.  
      Closing or opening the departments for monitoring
    15.  
      Deleting departments
  6. Managing department users
    1.  
      Assigning users to departments
    2.  
      Removing users from departments
    3.  
      Adding new roles for users
    4.  
      Removing roles
    5. Managing role assignment for a user in departments
      1.  
        Assigning departments and exceptions to specific users
      2.  
        Removing a specific role to users in one or more departments and exceptions
  7. Managing department-level archives
    1.  
      About department-level archives
    2.  
      Including or excluding enterprise vault archives at department-level
  8. Managing department-level searches
    1.  
      About department-level searches
    2.  
      Guidelines for effective searches
    3.  
      Creating and running department-level searches
    4.  
      Pausing and resuming searches
    5.  
      Downloading search details for archives
    6.  
      Disabling scheduled searches
    7.  
      Previewing search results
    8.  
      Accepting search results
    9.  
      Rejecting a search result
    10.  
      Resubmitting a search
  9. Managing department-specific hotword sets
    1.  
      Overview
    2.  
      Creating department-specific hotword sets
    3.  
      Editing department-specific hotwords and hotword sets
    4.  
      Deleting department-specific hotword sets
  10. Managing department-specific labels
    1.  
      Searching department-specific labels, label groups, and single choice groups
    2.  
      Managing department-specific labels
    3.  
      Managing department-specific label groups
    4.  
      Managing department-specific single choice label groups
  11. Managing department-specific review comments
    1.  
      About department-level review comments
    2.  
      Adding department-level review comments
    3.  
      Editing department-level review comments
    4.  
      Deleting department-level review comments
    5.  
      Updating order of department-level review comments
  12. Viewing employees associated with departments
    1.  
      Viewing employee association history
  13. Managing users, roles, and permissions
    1.  
      Overview
    2.  
      Predefined user roles and permissions
    3.  
      Adding new roles for users (employees) and employee groups
    4.  
      Editing user roles and permissions
    5.  
      Deleting user roles
    6.  
      Assigning Veritas Surveillances to users (employees) and employee groups
    7.  
      Restricting users to use hotwords in searches
    8.  
      Removing a user role
  14. Managing application-level archives
    1.  
      About application-level archives
    2.  
      Including or excluding enterprise vault archives at application-level
  15. Managing application-level searches
    1.  
      About application-level searches
    2.  
      Viewing existing application-level searches
    3.  
      Creating and running application-level searches
    4.  
      Editing application-level searches
    5.  
      Excluding departments from application searches
    6.  
      Reinstating the excluded department for application searches
  16. Managing application-specific hotword sets
    1.  
      Overview
    2.  
      Creating application-specific hotword sets
    3.  
      Editing application-specific hotwords and hotword sets
    4.  
      Deleting application-specific hotword sets
  17. Managing application-specific labels
    1.  
      Searching application-specific labels, label groups, and single choice groups
    2.  
      Managing application-specific labels
    3.  
      Managing application-specific label groups
    4.  
      Managing application-specific single choice label groups
  18. Managing application-specific review comments
    1.  
      About application-level review comments
    2.  
      Adding application-level review comments
    3.  
      Editing application-level review comments
    4.  
      Deleting application-level review comments
    5.  
      Updating order of application-level review comments
  19. Managing search schedules
    1.  
      Overview
    2.  
      Setting up new search schedules
    3.  
      Setting up one-time search schedules
    4.  
      Example of a one-time search schedule
    5.  
      Setting up recurring search schedules
    6.  
      Example of a recurring search schedule
    7.  
      Editing search schedules
    8.  
      Deleting search schedules
  20. Managing export operations
    1.  
      About exporting items
    2.  
      Performing export runs
  21. Managing reviews
    1.  
      About reviewing with Veritas Surveillance
    2.  
      Understanding the Review page
    3.  
      Rearranging columns in the item list pane
    4.  
      Changing the Preview pane position
    5.  
      Filtering the items in the Review pane
    6.  
      Reviewing the Audio-Video Transcript type items
    7.  
      Reviewing searched items
    8.  
      Viewing Intelligent Review Details
    9.  
      Adding or removing text for machine learning
    10.  
      Assigning review status to items
    11.  
      Viewing hotwords highlighting
    12.  
      Viewing hotwords in collaboration message
    13.  
      Viewing tags highlighting
    14.  
      Viewing tags in collaboration message
    15.  
      Viewing the full content in a new window
    16.  
      Adding comments to items
    17.  
      Escalating the review items
    18.  
      Viewing history of items
    19.  
      Printing and downloading the items and attachments
  22. Working with reports
    1.  
      About Veritas Surveillance reports
    2.  
      Accessing data through the Microsoft SQL Server Reporting Services (SSRS)
    3. Enhanced reporting
      1.  
        Configuring a reporting endpoint
      2.  
        Authentication
      3. Departments API
        1.  
          Departments - List
      4. Roles API
        1.  
          Roles - List
        2.  
          Roles - List by filters
      5. Users API
        1.  
          Users - List
      6. UserRoles API
        1.  
          UserRoles - List by filters
      7. ItemMetrics API
        1.  
          ItemMetrics - List
        2.  
          ItemMetrics - List by filter
      8. ReviewerMapping API
        1.  
          ReviewerMapping - List
      9. MonitoredEmployees API
        1.  
          MonitoredEmployees - List
      10.  
        Evidence Of Review Async API
      11. Evidence of Review API
        1.  
          EvidenceOfReview - List by filter
      12.  
        Report Status API
      13.  
        Supported OData query options
      14.  
        Supported reporting endpoint API filters and their values
      15.  
        Responses
    4. Managing Power BI templates for reporting APIs
      1.  
        Configuring Microsoft Power BI Templates for Reporting APIs
      2.  
        Accessing Veritas Surveillance reports and datasets through the OData web service
      3.  
        Guidelines for using Veritas Surveillance templates with Microsoft Power BI Desktop
      4.  
        TEMPLATE - Item Metrics
      5.  
        TEMPLATE - Reviewer Mapping
      6.  
        TEMPLATE- Evidence Of Review - Submit report request
      7.  
        TEMPLATE- Evidence Of Review - View report data
      8.  
        Saving, editing, and refreshing the Power BI reports
  23. Managing Audit Settings
    1.  
      Audit Settings Overview
    2.  
      Editing the Audit Settings
  24. Working with Audit viewer
    1.  
      About Audit viewer
    2.  
      Performing a search for audit records

Creating and running application-level searches

To understand the prerequisites, See About application-level searches.

To create and run an application-level search

  1. In the left navigation pane, click Application.
  2. In the Searches tab, click New Search.

    The Create New Search dialog box appears. If the sections in this dialog box are in the collapsed state, expand them to view the corresponding fields.

  3. In the Search Type section, specify the relevant information in the following fields.

    The New Search dialog box appears. This section identifies the search and specifies when it runs.

    Search In

    Displays the departments in which the search will run. In the case of an application-wide search, by default this value is <All Departments>.

    Based on search

    Select an existing search as the basis on which you can set the criteria for the new search.

    Search Type

    Select the type of search as needed.

    • Select the Immediate option to run the search immediately upon creation.

    • Select the Scheduled option to specify a period during which the search is to run. Specify the schedule run start date and end date.

    • Select the Guaranteed Sample option to run the search at the selected sampling time, which is 1:00 A.M. by default. Select the Enabled check box to enable the search.

    Name

    Type a name for the search.

    Include items already in review

    Select this check box to specify whether the search results can include the items you previously captured and added to this department's review set. This option does not apply to the items you previously included in the review sets for other departments.

    For an immediate search or scheduled search, you can select this box to ensure that the results include the items that may already be in review from other searches.

    Search Schedule

    Select a required search schedule based on which the search runs at set times or set intervals.

    Schedule run start date

    Select a date on which the search needs to run.

    Schedule run end date

    Select a date on which the search needs to stop running.

  4. In the Sampling section, specify the relevant information in the following fields.

    This section lets you sample the search results and add a random selection of items to the review set.

    Sampling percentage

    Specify the percentage of search results to include in the review set. You can specify fractions, as in 10.25.

    You cannot change the sampling percentage if the owner of the department has locked this setting in the department properties.

    Set minimum items per author

    Specify the minimum number of items per author to include in the review set. If there are no items for an author in the search results, none can be included in the sample.

    Note:

    As the authors can be from outside the selected department, searches may return more results.

    Set absolute item limit

    Specify an upper limit on the total number of search results to add to the review set. This option takes precedence over any values that you set in the Sampling percentage field.

  5. In the Date range section, specify the relevant information in the respective fields.

    This section lets you search for items according to when they were sent or received.

    Specific date range

    Specify the date and time duration to search items that were sent or received during the selected period.

    Today / Yesterday / Last 7 days / Last 14 days / Last 28 days

    The date ranges are relative to when the search runs, which is today in the case of an immediate search.

    You may find these options useful when creating a scheduled, recurrent search that runs once every day, week, two weeks, or four weeks. For example, if the search runs once a week, select Last 7 days to limit the range to the days since the search last ran.

    Since search last ran

    For a scheduled search only, lets you search the new items that have arrived since the last time you ran the search. This option is similar to options such as Today and Yesterday. However, it lets you set an explicit start date for the first run of the search. By default, this option searches from the date of the last run (or the start date for the first search) to the current day minus 1 (that is, up to yesterday).

  6. In the Authors and recipients section, specify the relevant information in the following fields.

    This section targets the departments for the search and the direction of the items to search. Any departments that you have organized into partitions can only search items to and from departments in the same partition.

    Message Route

    Specify the departments you wish to search as well as the direction of the items you wish to search. Search for the items that are to or from the selected departments, and for the items that have traveled between the selected departments and other departments.

    You can search for the items that follow the following message route:

    • Between "the specified department" and

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    • TO "the specified department" from

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    • FROM "the specified department" to

      • custom addresses / domains

      • any department within the organization

      • department outside the organization

      • department internal AND/OR External to organization

    Any of / All of

    To search within department tags, select a department. To search within the To/From fields, only select the employees.

    You can expand the department tag to select monitored employees. If there are a large number of employees in the department, you can click the search icon in front of the department tag, which opens a new window where you can search and select monitored employees.

    Use inheritance, automatically include new departments

    Specify whether to apply the search to the subdepartments of the selected departments.

    By default, any new departments that are subdepartments of others automatically inherit any active, recurring searches that are applied to those departments. This is also true of any existing departments that you move under departments that have recurring searches.

    Department tree

    Specify the departments you want to include in the search. Click the arrows to the left of the department names to expand them and view the nested departments.

    Freeform email addresses / domains

    This field is available for all possible message routes. Type one or more email addresses and domains.

    Type each address or domain on a line of its own to search for the items where the From, To, CC, or BCC fields contains any of the addresses or domains. Type all the addresses and domains on a single line to search for items in which they are all present.

    Place the minus sign (-) in front of an address or domain to exclude it from the search. To exclude multiple addresses or domains, type them all on a single line.

    Note:

    You can use Freeform email addresses / domains to search for email addresses associated with the user accounts but now use the discontinued domain.

    To search for previously monitored employees, you should use department internal AND/OR External to organization message route, and then use the Freeform email addresses / domains option to provide email addresses or domains.

  7. In the Search terms section, specify the relevant information in the following fields.

    This section specifies the words or phrases for which the application should search in the subject lines of items and their bodies. By default, when you search for words in both the subject of an item and its content, the application finds those items that meet one or both criteria. However, it is possible to set up the application so that only those items that meet both criteria are found.

    Subject

    Type the keywords or phrases to be searched in the review items either in their subject lines or in the file names of their attachments. Press Enter to separate keywords and phrases from each other.

    Alternatively, click Hotwords to select hotword sets and keywords.

    Note:

    • Use an asterisk (*) wildcard to represent zero or more characters in your search. Use a question mark (?) wildcard to represent any single character. A wildcard search always finds items that match your search criteria and that were archived in Veritas Surveillance.

    • Use a minus sign (-) to indicate you want to exclude from the search results any items that contain the following word or phrase.

      For example, the search to find the items that contain either of the words Agent and Agency, but do not contain the word Cost. ("(Agent AND NOT Cost) OR (Agency AND NOT Cost)"):

      Any of: Agent -Cost

      Agency - Cost

    • A search term cannot comprise an excluded word or phrase only. When you specify such words or phrases, you must also specify a positive word or phrase you want to appear in the search results.

    • A search term cannot start with any of the following characters on any line: = + - @. For example, "Agent -Cost" is a valid search term but "-Cost Agent" is not.

    • Veritas Surveillance ignores any non-alphanumeric characters in the search term, except for those that have special significance, such as the plus sign, minus sign, and question mark. For example, a search for the term US@100 may find instances not only of US@100 but also of US 100 and US$100. Including non-alphanumeric characters in the search term may therefore return more results than you expect.

    Content

    Specify the keywords or phrases to be searched in the content of review items.

    Alternatively, click Hotwords to select hotword sets and keywords.

  8. In the Attachments section, specify the relevant information in the respective fields.

    This section lets you search for items of a certain size and type or that have the specified retention category.

    Number

    Specify the required number of attachments.

    You can search the items with specific number and type of attachments. The default option, Does not matter, means that the item can have zero or more attachments.

    All following other options require you to type one or two values that specify the required number of attachments:

    • Equals: requires a specific number of attachments.

    • Between: requires the number of attachments messages must have to a value between those to be specified.

    • Less than: requires a number of attachments below the number specified.

    • Greater than: requires any number of attachments greater than the number specified.

    File extensions

    Specify the file name extensions of particular types of attachments for which to search. Separate the extensions with space characters.

    For example, type the following to search for items with HTML or Microsoft Excel file attachments:.htm .xls.

    This search option evaluates attachments by their file names only; it does not check their file type. For example, suppose that a user changes the file name extension of a .zip file to .zap and then sends the renamed file as an email attachment. An Veritas Surveillance search for items that have attachments with a .zip extension does not find the email with the renamed attachment. The contents of some attachments may not be searchable because Enterprise Vault has not indexed them. In particular, file formats such as Fax and Voice do not have any indexable content. Some Enterprise Vault registry entries prevent it from indexing the contents of selected file types.

  9. In the Miscellaneous section, specify the relevant information in the respective fields.

    This section lets you search for items of a certain size and type or that have the specified retention category.

    Message size

    Specify the size in kilobytes of each item for which to search, as reported by the message store (Exchange, Domino, and so on). The item size includes the size of any attachments.

    The following options are available:

    • Does not matter: any number from 0 upward can be attached.

    • Equals: requires a specific number of attachments.

    • Between: requires the number of attachments messages must have to a value between those to be specified.

    • Less than: requires a number of attachments below the number specified.

    • Greater than: requires any number of attachments greater than the number specified.

    Message type

    Displays a list of configured and enabled content sources for the customer.

    Select the All content sources check box to consider messages from all types of content sources simultaneously. When this option is selected, other options remain disabled.

    To select specific message type, clear the All content sources check box, and select one or more required options from the content sources available in the list.

  10. In the Tags section, specify the relevant information in the respective fields.

    This section lets you search for items according to the tags with which any additional policy management software has classified them.

    Filter

    Select any of the following options to search for the items that match certain classification policies. There are several types of policies:

    • Inclusions only: Select this option to include items that your policy management software has classified for inclusion in the review set that may contain the most serious offenses, such as swearing, racism, or insider trading.

    • Ignore inclusions: Select this option to ignore items that Veritas Information Classifier has classified for inclusion in the review set that may contain the most serious offenses, such as swearing, racism, or insider trading.

    • Exclusions only: Select this option to include spam items and newsletters that your policy management software may classify for exclusion from the review set.

    • Ignore exclusions: Select this option to ignore spam items and newsletters that your policy management software may classify for exclusion from the review set.

    • Categories only: Select this option to include categorized items that exhibit certain characteristics, such as containing Spanish text. This type of policy provides no information on whether an item should be included in or excluded from the review set.

    • Ignore inclusions and exclusions: Select this option to ignore inclusion and exclusion items.

    • Custom: Select this option and type the names of one or more policies. Separate multiple tag names with commas, like this:

      CustomTag1,CustomTag2

    • All: Select this option to include all tags.

    Note:

    Veritas Information Classifier (VIC) is required to classify items based on their content and metadata. Implementing VIC requires additional charges.

    Name

    Select tag names. Separate multiple tag names with commas, like this:

    CustomTag1,CustomTag2

  11. In the Custom attributes section, enter the appropriate values in the respective fields.

    The Custom attributes section lets you search for the items that have the specified attributes. When Enterprise Vault processes an item, it populates a number of the item's attributes with information and stores this information with the archived item. Some third-party software may also attach additional attribute information to items. If you know the name of an attribute that interests you, you can enter its details here as a custom attribute.

    The options are as follows:

    Include operator

    If you enter the details of both the attributes, use the options in the Include operator drop-down list to determine whether the search results should match any of the attributes or all of them.

    Free form attribute

    Set the appropriate values in the Attribute, Type, Operator, and Value fields.

    Attribute

    Specify the attribute name you want to search for. The attribute name is case-sensitive.

    Attribute name is a searchable system or the custom index properties such as subj for subject, crct for current retention category, natc for number of attachments, and so on. To search for attribute information that a third-party software has added to the X-Headers of SMTP items, add the prefix EVXHDR to the name of the required attribute. For example:

    EVXHDR.X-CompanyID

    Type

    Select the attribute type. The application supports the following three attribute types:

    • string

    • number

    • date

    Operator

    Based on attribute type, the application has the following Operators:

    • For String type - Any, All, Exact and Phrase

    • For number type - Equals and Between

    • For date type - No operator. It only supports range (from and to).

    Value

    Specify the terms you want to search. The attribute value is case-sensitive.

    Note:

    Do not enclose attribute values in quotation marks if you want to indicate that they are phrases. Instead, select Phrase as the operator for these attributes, if you have a choice. Alternatively, you can indicate that an attribute value is a phrase by replacing all the spaces with periods, as follows:

    sample.attribute.value

    This technique lets you specify multiple phrase values for the same custom attribute. For example, consider the following attribute value:

    Enterprise.Vault.Service.Account system VAS.Administrator

    This value matches "Enterprise Vault Service Account", "system", and "VAS Administrator".

  12. In the Intelligent Review section, choose options for the learning engine in Veritas Surveillance.

    This engine allows Veritas Surveillance to search for items intelligently, based on the actions that reviewers have taken on earlier items. For example, after a reviewer has marked a spam message or out-of-office reply as irrelevant then, when Veritas Surveillance detects other items that have similar characteristics, it can handle them in the same way.

    Note:

    Searches that use the intelligent review feature may take slightly longer to complete than those that do not use this feature.

    Searches, by default, consider metadata and content of items to determine the relevance. However, if search results contain items that are older than 30 days, only metadata is considered to determine the relevance.

    The options for Learning behavior are as follows:

    None

    Veritas Surveillance searches for items in the normal way, without implementing Intelligent Review. This is the default option.

    Search and prioritize

    Veritas Surveillance searches for both relevant items and irrelevant items without favoring one over the other. So, if your chosen Sampling percentage value requires that you capture and review 10% of items, Veritas Surveillance captures 10% - but a substantial number of the items may be irrelevant.

    With this option, however, Veritas Surveillance does give the items a status of either Unreviewed (Irrelevant) or Unreviewed (Relevant) as it adds them to the review set. When you later review the items in the Review pane, you can filter them by their Unreviewed status to distinguish between the relevant and irrelevant items.

    Search and then sample ONLY relevant content

    Veritas Surveillance searches across all the items and captures the relevant ones only, until it has captured the required percentage. So, if your chosen Sampling percentage value requires that you capture and review 10% of items, Veritas Surveillance captures 10% - all of them considered to be relevant.

    If there are too few relevant items to fulfil the chosen sampling percentage, Veritas Surveillance does not supplement them with irrelevant items. This is an important difference between this option and the equivalent option, Sample exact percentage of ONLY relevant content, in the Department Properties pane.

  13. Click Save.