Updated on 2026-09-24 GMT+08:00

Creating a Discovery Task

To perform database sensitive data discovery, you need to create a sensitive data discovery task.

To create a new discovery task, you must complete the following steps:

  1. Define the discovery task name.
  2. Select the database, schema, and table where sensitive data needs to be identified.
  3. Select the discovery method, matching rate, and the sensitive data domain to be discovered.

Procedure

  1. Logging In to the Database Encryption System using the system administrator (sysadmin) account .
  2. Select Project Management from the left navigation tree.
  3. When hovering the mouse over a project for which you need to create a discovery task, the project will display the following status, as shown in Figure 1.

    Figure 1 Creating a new discovery task

  4. Click Enter in the image above to navigate to the project management homepage. As shown in Figure 2.

    Figure 2 Project management home page
    • The Project Management Home Page displays the current system's basic information, including:
      • The current system comprises several databases. As shown in the figure above: 1.
      • How many tables does the current system contain? As shown in the figure above: 11.
      • How many fields does the current system contain? As shown in the figure above: 87.
      • How many tables involve encryption?
      • How many fields have been encrypted?
    • As well as the performance of the host machine running the database encryption system.
      • CPU Monitoring: Displays the number of server CPUs and their utilization rates.
      • Memory Monitoring: Displays total memory capacity and memory usage rate.
      • Disk space: Displays the disk usage status on the machine where the Database Encryption System is installed.

  5. Click the Discovery and Analysis menu on the left; then click Add Discovery Task in the top-right corner, as shown in Figure 3. This initiates the creation of a new sensitive data discovery task.

    Figure 3 Creating a new discovery task

  6. In the pop-up window, enter the Discovery Task Name and Remarks fields, then click Next, as shown in Figure 4. The parameter configuration instructions for the Discovery Task are provided in Table 1.

    Figure 4 Discovery configuration 1
    Table 1 Discovery task parameter specifications

    Parameter

    Description

    Discovery Task Name

    Custom string – fill in according to your actual business requirements.

    Remark

    Optional – please enter any additional notes.

  7. Click Next to proceed to the Data Source (Asset Database) Selection Interface, as shown in Figure 5.

    Figure 5 Discovery configuration 2
    • Data source: Select the data source (Asset Database) you wish to discover from the dropdown menu.
    • SCHEMA List: After selecting a data source, the system will automatically display all SCHEMAS that are available for use in this project.
    • Table List: Select a Schema; the right-hand table list will display all tables under that Schema. At this point, you can either use the Select All option to select all tables, or select the tables you wish to perform sensitive data discovery on one by one.

  8. Click Next to access the page shown in Figure 6; then select the sampling method, set the maximum sampling count, matching rate, and sensitivity type. The parameter descriptions are provided in Table 2.

    Figure 6 Discovery configuration 3
    Table 2 Sampling rule parameter configuration guide

    Parameter

    Description

    Sample Mode

    Sequence: Sampling is performed sequentially—that is, sampling is done based on the natural return values returned by the database.

    Maximum sampling count

    Number of sampling rows.

    Match Rate

    The proportion of data points in the sampled dataset that meet the discovery criteria.

    For example: when the maximum sampling size is 1000 and the matching rate is 30%, if the number of data records meeting the specified criteria reaches 300, the column is classified as containing specific sensitive data.

    Data Domain

    Select the sensitive data domain you wish to identify.

    For information on how to define data domains and their discovery rules, please refer to the Discovery Rule.

    Best practices for sensitive data discovery.

    • When conducting initial sensitive data discovery on an unfamiliar system, try to set the matching rate to a lower value (e.g., 10–20%) to ensure that all potentially sensitive data is identified. Once you become more familiar with the system, gradually increase the matching rate to improve the accuracy of data discovery. Adjust the rate progressively until it reaches an optimal value, thereby reducing the overall data cataloging workload.
    • Sensitive data discovery serves as an auxiliary tool and cannot guarantee 100% accuracy. After the discovery process is completed, manual verification is required to ensure the proper operation of the system.

  9. Click Add Sensitive Type to add the type of sensitive data you wish to discover.

    You can select multiple sensitive data domains, including specifying the discovery rules for each data domain (these rules must be configured in advance within the Data Domain module, or you may use the system's built-in sensitive data domain rules), as shown in Figure 7.

    Figure 7 Selecting the data domain and discovery rules to be discovered
    • Select the first checkbox: This selects all supported sensitive data fields.
    • Select the Start from Second checkbox individually: To select specific sensitive data fields, you can add them one by one.
    • Discovery Rule Selection: Each data field has a default discovery rule; the default discovery rule is selected by default. Alternatively, you can specify other discovery rules; as shown in Figure 8, for example, the Name field supports two different discovery rules.
      Figure 8 Selecting a specified data domain discovery rule

  10. After completing the parameter settings, click Confirm to proceed to the interface shown in Figure 9.

    Figure 9 Sensitive data domain discovery completed

  11. Click Confirm again to complete the discovery task; then save and exit.

    Automatically return to the Sensitive Data Discovery Task List, as shown in Figure 10.

    Figure 10 Sensitive data discovery task list