DLP Incident Manager/DLP Operations

Prev Next

Use the DLP Incident Manager module in ePO - On-prem to view the security events from policy violations. Use DLP Operations to view administrative information, such as information about client deployment.

DLP Incident Manager has three tabbed pages. On each page the Present drop-down list determines the data set displayed: Data-in-use/motion, Data-at-rest (Endpoint), or Data-at-rest (Network).

  • Analytics — A display of six charts that summarize the incident list. Each chart has a filter to adjust the display. The charts display:

    • Top 10 RuleSets

    • Incidents per Type

    • Top 10 Users with Violations

    • Number of Incidents Per Day

    • Top 10 Destinations

    • Top 10 Classifications

  • Incident List — The current list of policy violation events.

  • Incident Tasks — A list of actions you can take on the list or selected parts of it. They include assigning reviewers to incidents, setting automatic email notifications, and purging all or part of the list.

  • Incident History — A list with all historic incidents. Purging the incident list does not affect the history.

DLP Operations has four tabbed pages:

  • Operational Event List — The current list of administrative events.

  • Operational Event Tasks — A list of actions you can take on the list or selected parts of it, similar to the incident tasks.

  • Operational Event History — A list with all historic events.

  • User Information — Displays data from the user information table.

Detailed information can be viewed by drilling down (selecting) a specific incident or event.

User Information

The User Information page displays data from the user information table. The table is populated automatically from user information in incidents and operational events. You can add more detailed information by importing from a CSV file.

Information displayed typically includes user principal name (username@xyz), user log on name, user operational unit, first name, last name, user primary email, user manager, department, and business unit. The complete list of available fields can be viewed from the Edit command for the View option.