To quickly identify significant incidents, arrange the way incidents are listed based on attributes such as severity, incident type, classification, and the user logged on when the incident was detected.
Note
Incidents generated by Data Protection and Trellix Device Control rules are displayed in the Data In-Use / Motion category. In the Filter By pane, the Data In-Use / Motion is selected, by default.
In ePO - SaaS Protection Workspace, click the incidents in the Data Protection Overview to open the incident management workspace.
The incident management workspace opens.
Click the calendar icon to open the date range options menu. Choose a preset date range, or use the calendar to select a custom time and date range of incidents to display.
The selected range is displayed next to the calendar icon.
Select the checkboxes in the Filter By pane to filter the incidents by severity, status, resolution, the incident type, the classification, the user who triggered the incident, or the rule set. You can select checkboxes from different filters to drill-down the search.
Note
When you select a filter, attributes not held by incidents are not displayed in remaining filter criteria in the Filter By pane.
The filtered list of incidents is displayed in the Incidents pane.