Use filters to display incidents that match specified criteria.
Trellix DLP Endpoint Example: You suspect a particular user has been sending connections containing sensitive data to a range of IP addresses outside the company. You can create a filter to display incidents that match the user name and the range of IP addresses.
For details about product features, usage, and best practices, click ? or Help.
In ePO - On-prem, select DLP Incident Manager.
From the Present drop-down list, select the option for your product.
From the Filter drop-down list, select (no custom filter) and click Edit.
Configure the filter parameters.
From the Available Properties list, select a property.
Enter the value for the property.
Note
To add additional values for the same property, click +.
Select additional properties as needed.
Note
To remove a property entry, click <.
Click Update Filter.
Configure the filter settings.
Next to the Filter drop-down list, click Save.
Select one of these options.
Save as new filter — Specify a name for the filter.
Override existing filter — Select the filter to save.
Select who can use the filter.
Public — Any user can use the filter.
Private — Only the user that created the filter can use the filter.
Click OK.
Note
You can also manage filters in the incident manager by selecting Actions → Filter.