Incident History page

Prev Next

This page describes the DLP Incident Manager history page. Items purged from the Incident Event List page continue to be displayed on the history page.

Option definitions

Category

Option

Definition

Menu bar

Present (Incident History page only)

Drop-down list to display either Data-in-use/motion, Data-at-rest (Endpoint) (Trellix DLP Endpoint data), or Data-at-rest (Network) (Trellix DLP Discover data).

View

Drop-down list to display the view. Use Edit to create a view. The view can alternately be applied and switched off during the current session. Use Save to use a view between sessions.

Time (Trellix DLP Endpoint incidents only)

Drop-down list to display the time filter.

Scan (Trellix DLP Discover incidents only)

Opens the Select scan and run page to specify the scan and scan instance to display results for.

Filter

Drop-down list to select the display filter. Use Edit to create a filter. The available properties vary according to the Present setting. The filter can alternately be applied and switched off during the current session. Use Save to use a filter between sessions.

Incident display area

Incident list

Displays historical incidents based on the current selections.

Note

To add or remove columns, click Edit next to the View drop-down list.

Select all in this page

Selects all items displayed on the page.

Select all in all pages

Selects all items displayed on all pages.

Go to page

Specifies which page of the list to display.

Arrow buttons

Click to browse through pages.

Actions

Add Comment

Active when at least one incident is selected. Opens a text box for comments of up to 500 characters.

Email Selected Events

Opens an email set-up window to send selected events.

Release Redaction

Opens an authorization dialog box for entering user name and password.

Set Properties

Opens a dialog box that allows editing of properties (Severity, Status, and so forth) for all selected incidents.

Manage Labels

Opens dialog boxes to attach, detach, or delete labels.

View

Allows the user to customize the list view. Columns can be rearranged, displayed, or hidden. The view can be saved as a named view, with options for Save group by, Save time filter, and Save column filter. Saved views can be public or private.

Filter

Allows filters to be edited, saved, deleted, or exported to Incident Tasks. FilterEdit opens the Edit Filter Criteria page for selection and definition of filter parameters.

Export Device Parameters

(for Data in-use/motion incident list only

Exports the device parameters of selected incidents to a CSV file and displays the file name as a link. Displays an error message if the incident is not a device incident.