Updated on 2026-07-07 GMT+08:00

Discovering and Analysing

Discovery and organization refers to the automated process of identifying and organizing sensitive data within a project using the automated discovery tool provided by the Transparent Encryption Gateway. This process serves as the core operation for static data masking. When executing discovery tasks, the system identifies the data fields in tables based on the selected discovery rules.

Discovery refers to the process of identifying sensitive data in various databases or data storage systems using automated tools and built-in algorithms; it is an automated procedure.

The review process involves re-verifying automatically discovered results using expert knowledge, requiring human intervention. For detailed procedures, refer to the following chapter.

New Discovered Task

  1. Logging In to the Database Encryption System using the system administrator sysadmin account.
  2. In the left navigation bar, select Project Management.
  3. View the project list. hover over the project you want to edit to display the edit button; click it to proceed.
  4. Click Discovery and Analysis on the left. Click Add Discovery Task in the upper-right corner.

    Figure 1 New discovery tasks

  5. In the pop-up window, enter the name and remarks, then click Next.

    Figure 2 Discovering configuration
    Table 1 Table1 Description of newly added encryption project parameters

    Parameter

    Description

    Discover Task Name

    Custom string that can be filled in based on actual business needs.

    Remark

    Not mandatory; you can enter remarks.

  6. Select the table for the discovery task and click Next.

    Figure 3 Discovering configuration 2

  7. Set the sampling method and matching percentage.

    Figure 4 Selecting a sampling method
    Table 2 Table2 Description of sampling rule parameters

    Parameter

    Description

    Sampling Method

    • Sequential: Sample data in order.
    • Random: Sample data randomly.

    Maximum Sampling Number

    The amount of sampled data.

    Matching Rate

    Proportion of data volume falling within the sensitive category.

    Sensitive Type

    The data field has been configured (Configuration location: Rule Management-Discovery Rules; you can use the system's built-in data field or create a custom one).

  8. Click Add Sensitive Type to set the sensitive data type.

    You can select multiple data domains to use and choose the corresponding rules under each data domain (which need to be configured in advance in the data domain module, or you can use the system's built-in data domain rules).

    Figure 5 Selecting data field rules

  9. After completing the parameter settings, click Confirm to save and exit.

Viewing and Editing

  1. For successfully saved discovery identification strategies, you can view an overview on the page.

    Figure 6 Discovering and Sorting List

  2. Click Edit to modify the discovery rule again (the button is located above).

    Form parameter description: Refer to Figure 6.

    Figure 7 Discovery configuration 1

Discovering and Monitoring

  1. For successfully saved discovery identification strategies, discovery and monitoring operations can be performed.

    Figure 8 Discovering and sorting list
    Table 3 Table3 Task information list parameter description

    Parameter

    Description

    Discovery Task Name

    The current task name can be searched with fuzzy matching or modified by clicking Edit.

    Analysed Result

    The current completion rate for data discovery and organization.

    Database Type

    Show the target database type for the task.

    Operator

    The login username for the operation.

    Creation Time

    Task creation time.

    Modification Time

    Time to save after modifying the task.

    Remarks

    User-defined remarks.

    Find(Button)

    Execute the task to sort out findings.

    Monitoring (Button)

    Get specific task information.

    More

    Show other buttons.

  2. A confirmation prompt will appear before executing the task.

    Figure 9 Tip

  3. When execution is complete, the scanning percentage is displayed in real-time in the upper left corner of the page. The reason and time of any program or business error are shown in the lower left corner, while the discovery results (corresponding fields) appear on the right side.

    Figure 10 Discovering progress
    • Click the Monitoring button on the task to navigate to the discovery progress page mentioned above.
    • After clicking the Find Button, the discovery task will run in the background. Leaving the current page does not affect the task execution.
    • Note: This feature is primarily used when an operator leaves the discovery interface to perform other tasks while the task is running. To continue monitoring the progress, click the monitoring button.

Searching Results

  1. After completing the task, click View Results in the upper-right corner to see the Discovering and Monitoring.

    Figure 11 Discovering progress

  2. Display the result page.

    Figure 12 Viewing task result details

  3. (See the Figure 12) In the upper part of the results page, the Execution Report of Discovery Task is displayed, showing details such as execution time, total number of objects, number of discovered objects, and number of task objects.

    In the lower part of the result page, display detailed information about the discovery results, including field names, match rates, and other functional buttons.

  4. Prepare the data field (for matching fields, required algorithm categories, and specific encryption/decryption and anonymization algorithms).

    Click Batch Setting Rules to apply matching rules to fields in bulk.

    Figure 13 Batch rule configuration

  5. Click Set to open the Data Field Settings dialog. Select the appropriate data field rule, then click Confirm Rule to exit.

    Figure 14 Setting data area and field discovery rules

  6. Prepare to execute the confirmation rule (activate the identified or manually configured rule for subsequent encryption, decryption, or data masking operations).

    Use Confirm All or Cancel All to batch confirm or cancel rules.

    Figure 15 Confirming rules

  7. Click Match Preview to view the match results for data and rules.

    Figure 16 Matching preview

  8. In the pop-up window, view the specific match details.

    Figure 17 Preview data match results

  9. You can choose Import or Export to import or export the discovery results.

    Figure 18 Importing and exporting

  10. Click the Save button, enter the version name in the pop-up window, and save the current discovery results as a template.

    Figure 19 Saving the discovery template
    Table 4 Table4 Task version pop-up parameter description

    Parameter

    Description

    Version Name

    Users can customize saving the results of discovered tasks as versions based on their needs; up to three versions can be saved.

    Operator

    Login username for the saved version.

    Storage Time

    Version save time.

For Encryption Functionality

The saved discovery results can be used for Encryption Policy Settings.

  1. Logging In to the Database Encryption System using the system administrator sysadmin account.
  2. Select Project Management in the left navigation tree.
  3. Select the desired project and enter the project.
  4. In the left navigation tree, select Encryption Settings Management > Encryption Policy Settings.
  5. Select the desired data source, choose Batch Configuration, and then select Select Discovery Task Version.

    Figure 20 Finding and selecting the task version

  6. After selecting the appropriate version, click Batch Configuration to apply the corresponding fields and data domains from the discovery results to all relevant fields as the encryption policy and key matching results.

Supports Desensitization Functionality

For details, see Desensitization Strategy Management.

Smart Discovery

Intelligent Discovery primarily addresses the issues of redundant data discovery and redundant processing during sensitive data identification, significantly reducing the associated workload.

Figure 21 Smarting discovery

From the aforementioned analysis of discovery results and version preservation functionality, we observe that certain fields have been identified and marked as sensitive, stored in specific versions. The intelligent discovery mechanism achieves this by ensuring that fields identified as sensitive data are not redundantly detected. The following application example provides a clearer illustration of this intelligent discovery feature:

For example, during phone number detection, some system-encoded fields may also be marked as phone numbers, resulting in incorrect detection outcomes. In such cases, the Intelligent Discovery pane can be utilized to resolve these issues.

First, use the batch rule setup feature to reset the field rules that were incorrectly marked as phone numbers, then save as a version.

After executing the discovery task via the intelligent discovery feature, those fields will no longer be marked as phone numbers.

Viewing History

The History Feature demonstrates data organization for two distinct task versions.

  1. For successfully saved discovery and identification strategies, you can view the history. Click More, then select View History.
  2. Select both task versions, click the Search button, and compare the two versions in three aspects: data field of the same field, anonymization rules, and confirmation status (i.e., whether confirmation was completed).

    Alternatively, you can select the Only show different data option to remove identical data between the two versions, making the comparison results clearer.

    Figure 22 Result version comparison