Create an incident from a result
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next You can create a incident from the Search Results Details view or from a selected result in the list of searches.
In ePO - On-prem , select Menu → DLP Capture .
In the Search List , find the search whose results you want to create an incident from and click the number of results link.
In Search Results , either select the result and click Actions → Create Incident , or click a specific Result ID and click Actions → Create Incident .
An incident is added to the DLP Incident Manager and a link to it is added in the selected result's details.
Was this article helpful?
Yes No
Related articles
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > The DLP Capture Search feature > The Search List and Search Results
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.14.x Product Guide > The DLP Capture Search feature > The Search List and Search Results
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > The DLP Capture Search feature > The Search List and Search Results
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Incidents, events, and cases > View incidents