All Products
Search
Document Center

Data Security Center:View sensitive data identification results

Last Updated:Aug 26, 2026

After a sensitive data identification task is complete, you can view the scan results in Data Security Center. You can view results for database instances, OSS Buckets, Simple Log Service (SLS) Projects, or specific data objects, such as data tables, files, or data stored in five-minute intervals. This topic describes how to view the sensitive data identification results for data objects and database instances.

View the identification results for a database instance

To view the sensitive data identification results for a database instance, follow these steps.

  1. Log on to the Data Security Center console.

  2. In the navigation pane on the left, select Classification and Grading > Asset Insight.

  3. On the Asset Type tab, click a data type to view the sensitive data identification results for all connected database instances of that type.

    Note

    You can view sensitive data identification results from different dimensions on the Asset Type and Data Domain tabs. This topic uses the Asset Type tab as an example. You can also go to the Data Domain tab, select a data domain, and then view the identification results for the asset instances within that domain.

    Sensitivity level

    Description

    N/A

    No sensitive information defined in the current identification template was detected.

    S1

    Non-sensitive data. Disclosing this type of data is unlikely to cause harm in most situations. Examples: provinces, cities, and product names.

    S2

    Generally sensitive data. This type of data is not suitable for public disclosure, and a data breach would have a low impact. Examples: names and addresses.

    S3

    Critically sensitive data. This data is highly sensitive, and even a minor leak could cause serious harm. Examples: ID documents, account passwords, and database information.

    S4

    Core confidential data. This data should never be disclosed under any circumstances. Examples: genetic data, fingerprints, and iris scans.

  4. To view the details of sensitive data in a data asset instance, click Table details (for structured data and big data), Details (for unstructured SLS data), or File details (for unstructured OSS data) in the Actions column.

  5. In the details panel that appears on the right, you can view the sensitive data statistics.

    The sensitive data statistics panel contains the following modules:

    • Data Classification Statistics: A donut chart showing the proportion of each sensitivity level (such as S2 and S3).

    • Sensitive Data Tag Statistics: A donut chart showing the proportion of each data tag (such as Personal Information, Personal Sensitive Information, and General Information).

    • Data Identification Rate: A bar chart comparing the total number of columns with the number of sensitive columns and the identification rate.

    • Top 5 Hit Models: A bar chart showing the top 5 identification models by hit count (such as Personal Phone Number, Passport Number, and Mobile Phone Number).

    • The table at the bottom shows Table Name, Total Rows, Total Columns, Sensitive Columns, Data Tags, and Hit Data for each table, with a Column Details entry in the Actions column.

  6. In the sensitive data list, click Column details (for structured data and big data) or Hit details (for unstructured data) in the Actions column to view the details of the rules that were hit for each data column.

    If the Actions column contains a Revision entry, you can revise the sensitive data identification results.

    The column details page displays the identification results for each column in the table. The following information is included:

    • Column Name

    • Data Tags

    • Identification Result

    • Sensitivity Level (such as S1)

    • Revision Status

    • Data Sampling Result

    • Actions (including Revise and Restore links)

View the identification results for an OSS Bucket

To view the sensitive data identification results for an OSS Bucket, follow these steps.

  1. Log on to the Data Security Center console.

  2. In the navigation pane on the left, choose Classification and Grading > Asset Insight.

  3. On the Asset Type tab, click Unstructured Data > OSS in the navigation pane on the left. The page displays the sensitive data identification results for all OSS Buckets that are connected to Data Security Center. For information about the sensitivity level types and their descriptions, see the following table.

    Sensitivity level

    Description

    N/A

    No sensitive information defined in the current identification template was detected.

    S1

    Non-sensitive data. Disclosing this type of data is unlikely to cause harm in most situations. Examples: provinces, cities, and product names.

    S2

    Generally sensitive data. This type of data is not suitable for public disclosure, and a data breach would have a low impact. Examples: names and addresses.

    S3

    Critically sensitive data. This data is highly sensitive, and even a minor leak could cause serious harm. Examples: ID documents, account passwords, and database information.

    S4

    Core confidential data. This data should never be disclosed under any circumstances. Examples: genetic data, fingerprints, and iris scans.

  4. Click File details in the Actions column of the target bucket.

  5. In the OSS object query panel, you can view the following sensitive data statistics:

    • Data Classification Statistics: A donut chart showing the number of files that were hit and the proportion of each sensitivity level (such as S4).

    • Data Identification Rate: A bar chart comparing the total number of files with the number of sensitive files.

    • Top 5 Hit Models: A horizontal bar chart showing the top 5 identification models by hit count (such as Name, Nationality, and City).

    • The filter bar at the bottom supports filtering results by Hit Model and Sensitivity Level.

    • The results table contains File Name, File Size (Bytes), Type, Hit Count, Hit Model Count, Last Modified Time, and Actions columns. Click Hit Details in the Actions column to view the specific hit information for a file.

  6. Click Hit details in the Actions column for a sensitive file. In the Hit query panel, you can view the details of the sensitive information in the file. This includes the Hit Model, Sensitivity Level, Number of Hits, and Data sampling result.

  7. Click the File name above the list to go to the OSS console and view the file details.

    Note

    The path that you are redirected to after you click the file name is the file path that Data Security Center obtained during the scan. If you moved the file, the path may be outdated. You can run the identification task again on the Data Classification > Tasks > Identification Tasks tab.

View the identification results for SLS

To follow the sensitive data detection results for an OSS bucket, perform the following steps.

  1. Log on to the Data Security Center console.

  2. In the navigation pane on the left, choose Classification and Grading > Asset Insight.

  3. On the Asset Type tab, click Unstructured Data in the navigation pane on the left. The page displays the sensitive data identification results for all Simple Log Service projects that are connected to Data Security Center. For information about the sensitivity level types and their descriptions, see the following table.

    Sensitivity level

    Description

    N/A

    No sensitive information defined in the current identification template was detected.

    S1

    Non-sensitive data. Disclosing this type of data is unlikely to cause harm in most situations. Examples: provinces, cities, and product names.

    S2

    Generally sensitive data. This type of data is not suitable for public disclosure, and a data breach would have a low impact. Examples: names and addresses.

    S3

    Critically sensitive data. This data is highly sensitive, and even a minor leak could cause serious harm. Examples: ID documents, account passwords, and database information.

    S4

    Core confidential data. This data should never be disclosed under any circumstances. Examples: genetic data, fingerprints, and iris scans.

  4. Click Details in the Actions column of the target Logstore.

  5. In the Simple Log Service Object Query panel, you can view the following sensitive data statistics:

    • Data Classification Statistics: The donut chart on the left shows the number of hit tables and the proportion of each sensitivity level. The right side shows model and tag information.

    • Top 5 Hit Models: A bar chart showing the top 5 models by hit count.

    • The data table at the bottom contains Data Object, Hit Count, Hit Model Count, Sensitivity Level, Scan Time, and Actions columns, with support for filtering data by using the Hit Model and Sensitivity Level drop-down menus. Click Hit Details in the Actions column to view the specific hit information.

  6. Click Hit details in the Actions column of a data object to view the Hit Model, Sensitivity Level, Number of Hits, and Data sampling result.

  7. Click a result in the Data sampling result column to go to the corresponding Logstore. The logs are filtered based on the sampling result.

Simple Log Service limits

The following limits apply when you go to Simple Log Service to query logs based on sampling results:

  • Field index

    • Index not created: If an index is not created, an error message is displayed when you filter logs based on sampling results.

      The error code is IndexConfigNotExist, indicating that the Logstore index is not enabled. To query and analyze logs, click to enable the index.

      Click Enable in the upper-right corner of the page. In the Query and Analysis panel, configure the index, tokenizers, and other settings. For more information, see Create an index.

    • Index created: If an existing index does not cover the fields to be retrieved, the query may return no results. You can adjust the field configuration of the index to include the required fields based on your query requirements.

  • Account permissions: If you use a Resource Access Management (RAM) user, make sure that the user has the read-only permission for logs (AliyunLogReadOnlyAccess).