This page describes the DLP Incident Manager history page. Items purged from the Incident Event List page continue to be displayed on the history page.
Category | Option | Definition |
|---|---|---|
Menu bar | Present (Incident History page only) | Drop-down list to display either Data-in-use/motion, Data-at-rest (Endpoint) (Trellix DLP Endpoint data), or Data-at-rest (Network) (Trellix DLP Discover data). |
View | Drop-down list to display the view. Use Edit to create a view. The view can alternately be applied and switched off during the current session. Use Save to use a view between sessions. | |
Time (Trellix DLP Endpoint incidents only) | Drop-down list to display the time filter. | |
Scan (Trellix DLP Discover incidents only) | Opens the Select scan and run page to specify the scan and scan instance to display results for. | |
Filter | Drop-down list to select the display filter. Use Edit to create a filter. The available properties vary according to the Present setting. The filter can alternately be applied and switched off during the current session. Use Save to use a filter between sessions. | |
Incident display area | Incident list | Displays historical incidents based on the current selections.
|
Select all in this page | Selects all items displayed on the page. | |
Select all in all pages | Selects all items displayed on all pages. | |
Go to page | Specifies which page of the list to display. | |
Arrow buttons | Click to browse through pages. | |
Actions | Add Comment | Active when at least one incident is selected. Opens a text box for comments of up to 500 characters. |
Email Selected Events | Opens an email set-up window to send selected events. | |
Release Redaction | Opens an authorization dialog box for entering user name and password. | |
Set Properties | Opens a dialog box that allows editing of properties (Severity, Status, and so forth) for all selected incidents. | |
Manage Labels | Opens dialog boxes to attach, detach, or delete labels. | |
View | Allows the user to customize the list view. Columns can be rearranged, displayed, or hidden. The view can be saved as a named view, with options for Save group by, Save time filter, and Save column filter. Saved views can be public or private. | |
Filter | Allows filters to be edited, saved, deleted, or exported to Incident Tasks. Filter → Edit opens the Edit Filter Criteria page for selection and definition of filter parameters. | |
Export Device Parameters (for Data in-use/motion incident list only | Exports the device parameters of selected incidents to a CSV file and displays the file name as a link. Displays an error message if the incident is not a device incident. |