Skip to main content
NetApp Data Classification

Manage saved queries with NetApp Data Classification

Contributors netapp-ahibbard

NetApp Data Classification lets you save search queries and create custom filters to find data in the Investigation page. You can use predefined queries or create saved queries and policies to act on matching data.

The Saved queries tab in the Compliance dashboard lists all the predefined and custom saved queries available on this instance of Data Classification.

You can convert saved queries to policies. Whereas queries filter data, policies allow you to act on the data. With a policy, you can delete discovered data or send email updates about it.

Saved queries also appear in the list of filters in the Investigation page.

A screenshot of the Saved queries tab in the Data Classification dashboard.

View saved queries results in the Investigation page

To display saved query results in the Investigation page, select the More button button for a search, then select Investigate Results.

A screenshot of selecting Investigate Results for a specific search from the Saved query tab.

Create saved queries and policies

You can create custom saved queries that return results specific to your organization. Results are returned for all files and directories (shares and folders) that match the search criteria.

Steps
  1. In the Investigation tab, define a search by selecting the filters you want to use. See Filtering data in the Investigation page for details.

  2. Once you have all the filter characteristics configured, select Save query.

    Screenshot showing how to save a filtered query as a Saved query.

  3. Name the saved query and add a description. The name must be unique.

  4. You can optionally save the query as policy:

    1. To save the query as a policy, switch the Run as a policy toggle.

    2. Choose to Delete permanently or Send email updates. If you choose email updates, you can email the query results to all Console users at daily, weekly, or monthly. Alternately, you can send the notification to specific email address at the same frequencies.

  5. Select Save.

    A screenshot that shows how to configure the Saved query and save it.

Once you have created the search or policy, you can view it in the Saved queries tab.

Edit saved queries or policies

You can modify the name and description of a saved query. You can also convert a query to a policy and vice versa.

You cannot modify default saved queries or the filters of an existing saved query. Instead, view the saved query's investigation results, change the filters, and save the result as a new query or policy.

Steps
  1. From the Saved queries page, select Edit Search for the search that you want to change.

    A screenshot showing Edit saved query.

  2. Make changes to the name and description fields.

    You can optionally convert the query to a policy or convert the policy to a saved query. Switch the Run as a policy toggle as needed.
    .. If you're converting the query to a policy, choose to Delete permanently or Send email updates. If you choose email updates, you can email the query results to all Console users daily, weekly, or monthly. Alternatively, you can send the notification to a specific email address at the same frequencies.

  3. Select Save to complete the changes.

Delete saved queries

You can delete any custom saved query or policy if you no longer need it. You can't delete default saved queries.

To delete a saved query, select the More button button for a specific search, select Delete query, then select Delete query again in the confirmation dialog.

Default queries

Data Classification provides the following system-defined search queries:

  • Data Subject names - High risk

    Files with more than 50 data subject names

  • Email Addresses - High risk

    Files with more than 50 email addresses or database columns with more than 50% of their rows containing email addresses

  • Personal data - High risk

    Files with more than 20 personal data identifiers or database columns with more than 50% of their rows containing personal data identifiers

  • Private data - Stale over 7 years

    Files containing personal or sensitive personal information, last modified more than seven years ago

  • Protect - High

    Files or database columns that contain a password, credit card information, IBAN number, or social security number

  • Protect - Low

    Files that have not been accessed for more than three years

  • Protect - Medium

    Files or database columns that contain personal data identifiers, including ID numbers, tax identification numbers, driver's license numbers, medical IDs, or passport numbers

  • Sensitive Personal data - High risk

    Files with more than 20 sensitive personal data identifiers or database columns with greater than 50% of their rows containing sensitive personal data