Incident Details pane

Prev Next

You can see detailed information about the selected incident in the Incident Details pane and the action taken to prevent data loss. The pane displays different options whether you have selected a single or multiple incidents.

Incident Details option details — single incident selected

Category

Option

Definition

Incident Details

Occurred

Displays the date and time the incident occurred.

Incident ID

Displays a unique number for each incident.

Action taken

Displays the action taken by Trellix DLP – SaaS.

Expected action

Displays the expected action taken by Trellix DLP – SaaS.

Severity

Change the severity of an incident.

Status

Change the status of an incident.

Resolution

Change the resolution of an incident.

User

Displays the user who triggered the incident.

Device

Displays the device in which the incident has occurred.

Reviewer

Add a reviewer to an incident.

Other details

Additional Information

Displays details of the endpoint, URL, and the device details in which the incident has occurred.

Evidence

Displays the evidence files associated with the incident. Clicking the file name opens the Evidence Details pane.

Justification

Displays details of the justification definition associated with the incident.

Policy and Rules

Displays the policy and rule that triggered the incident.

Classifications

Displays the classification criteria identified when the rule was triggered.

Collaboration

Displays the internal and external collaborators associated with the incident (only applies to incidents detected by Skyhigh Security Cloud).



Incident Details option details — multiple incidents selected

Category

Option

Definition

General

Severity

Change the severity of multiple incidents.

Status

Change the status of multiple incidents.

Resolution

Change the resolution of multiple incidents.

Reviewer

Change the reviewer of multiple incidents.