Use the DLP Incident Manager module in ePO - On-prem to view the security events from policy violations. Use DLP Operations to view administrative information, such as information about client deployment.
DLP Incident Manager has three tabbed pages. On each page the Present drop-down list determines the data set displayed: Data-in-use/motion, Data-at-rest (Endpoint), or Data-at-rest (Network).
Analytics — A display of six charts that summarize the incident list. Each chart has a filter to adjust the display. The charts display:
Top 10 RuleSets
Incidents per Type
Top 10 Users with Violations
Number of Incidents Per Day
Top 10 Destinations
Top 10 Classifications
Incident List — The current list of policy violation events.
Incident Tasks — A list of actions you can take on the list or selected parts of it. They include assigning reviewers to incidents, setting automatic email notifications, and purging all or part of the list.
Incident History — A list with all historic incidents. Purging the incident list does not affect the history.
DLP Operations has four tabbed pages:
Operational Event List — The current list of administrative events.
Operational Event Tasks — A list of actions you can take on the list or selected parts of it, similar to the incident tasks.
Operational Event History — A list with all historic events.
User Information — Displays data from the user information table.
Detailed information can be viewed by drilling down (selecting) a specific incident or event.
User Information
The User Information page displays data from the user information table. The table is populated automatically from user information in incidents and operational events. You can add more detailed information by importing from a CSV file.
Information displayed typically includes user principal name (username@xyz), user log on name, user operational unit, first name, last name, user primary email, user manager, department, and business unit. The complete list of available fields can be viewed from the Edit command for the View option.