What Feeds Defend
Defend reads runtime events from Targets of typedlp. A
dlp Target receives its events from a Dome proxy. It runs no scans, and no
Collector reports into it.
Create one with
vijil discover deployment-create --name "<name>" --type dlp. See
Create and Manage Targets.dlp Target configured, Defend loads and reports no events.
Scope the View
Two controls sit above everything else. Both change every number below them.Read the Counters
An errored event means the Guardrail failed to reach a verdict, so the traffic passed
unchecked. Watch this counter.
Unattributed flagged counts detections that Dome failed to tie to a registered Agent.
Any number above zero means traffic is routing through the proxy from a source your
Agent Registry is missing.
Read the Charts
Group DLP label totals by Detector to see which rule is firing, or by Agent to see where.
An Input detection is something a user sent toward an Agent. An Output detection is
something an Agent was about to send back.
Read the Events Table
The table below the charts lists individual detections. Filter it by Input or Output.
Expand a row for the full event.
Read the Same Data From the Command Line
Next Steps
Configure Guardrails
Change what Dome enforces for an Agent.
Observability
Per-Agent Guard execution logs and telemetry.