How the Incident Manager works

Prev Next

The Incident Manager Incident List tab has all the functionality required for reviewing policy violation incidents. Event details are viewed by clicking a specific event. You can create and save filters to change the view or use the predefined filters in the left pane. You can also change the view by selecting and ordering columns. Color-coded icons and numeric ratings for severity facilitate quick visual scanning of events.

Note

To display the User Principal Name and User Logon Name in Trellix DLP Network incidents, add an LDAP server to the DLP Appliance Management policy (Users and Groups category). You must do this even if your email protection rules do not use LDAP.

The Incident List tab works with ePO - On-prem Queries & Reports to create Trellix DLP Endpoint and Trellix DLP Network reports, and display data on ePO - On-prem dashboards.

Operations you can perform on events include:

  • Case management — Create cases and add selected incidents to a case

  • Comments — Add comments to selected incidents

  • Email events — Send selected events

  • Export device parameters — Export device parameters to a CSV file (Data in-use/motion list only)

  • Labels — Set a label for filtering by label

  • Release redaction — Remove redaction to view protected fields (requires correct permission)

  • Set properties — Edit the severity, status, or resolution; assign a user or group for incident review

incident manager


The DLP Operations page works in an identical manner with administrative events. The events contain information such as why the event was generated and which Trellix DLP product reported the event. It can also include user information connected with the event, such as user logon name, user principal name (username@xyz), or user manager, department, or business unit. Operational events can be filtered by any of these, or by other parameters such as severity, status, client version, policy name, and more.

DLP Operations
DLP Operations


Incident tasks/Operational Event tasks

Use the Incident Tasks or Operational Event Tasks tab to set criteria for scheduled tasks. Tasks set up on the pages work with the ePO - On-prem Server Tasks feature to schedule tasks.

Both tasks tabs are organized by the task type (left pane). The Incident Tasks tab is also organized by incident type, so that it is actually a 4 x 3 matrix, the information displayed depending on which two parameters you select.

Data in-use/motion

Data at-rest (Endpoint)

Data at-rest (Network)

Data in-use/motion (History)

Set Reviewer

X

X

X

Automatic mail notification

X

X

X

Purge events

X

X

X

X

Purge evidence files

X

X

X

X

Use case: Setting properties

Properties are data added to an incident that requires follow-up. You can add the properties from the details pane of the incident or by selecting ActionsSet Properties. The properties are:

  • Severity

  • Status

  • Resolution

  • Reviewing Group

  • Reviewing User

The reviewer can be any ePO - On-prem user. The reason severity can be changed is that if the administrator determines that the status is false positive, then the original severity is no longer meaningful.

Use case: Changing the view

In addition to using filters to change the view, you can also customize the fields and the order of display. Customized views can be saved and reused.

Creating a filter involves the following tasks:

  1. To open the view edit window, click ActionsViewChoose Columns.

  2. To move columns to the left or right, use the x icon to delete columns, and the arrow icons.

  3. To apply the customized view, click Update View.

  4. To save for future use, click ActionsViewSave View.

    Note

    When you save the view, you can also save time and custom filters. Saved views can be chosen from the drop-down list at the top of the page.