This page provides administrators with a list of events triggered by policy rules. The list can be filtered for easier viewing.
The Incident List displays only policy violations. Administrative events such as agent updates are displayed in a separate console, DLP Operational Events.
Option | Definition | |
|---|---|---|
Data-in-use/motion | Displays Trellix DLP Endpoint, Trellix Device Control, Trellix DLP Network Monitor, or Trellix DLP Network Prevent data. The Reporting Product column identifies which product produced the incident. | |
Data-at-rest (Endpoint) | Displays Trellix DLP Endpoint discover data | |
Data-at-rest (Network) | Displays Trellix DLP Discover data | |
Note
Only options for installed software are displayed.
Category | Option | Definition |
|---|---|---|
Menu bar | View | Drop-down list to display the view. Use Edit to create a view. The view can alternately be applied and switched off during the current session. Use Save to use a view between sessions. |
Time (Trellix DLP Endpoint only) | Drop-down list to display the time filter. | |
Scan (Trellix DLP Discover only) | Opens the Select scan and run page to specify the scan and scan instance to display results for. | |
Filter | Drop-down list to select the display filter. Use Edit to create a filter. The available properties vary according to the Present setting. The filter can alternately be applied and switched off during the current session. Use Save to use a filter between sessions. | |
Group by | Drop-down list to organize data. The available filters vary according to the Present setting. | |
Search | Text box for searching the data. | |
Incident display area | Incident list | Displays incidents based on the current selections.
|
Select all in this page | Selects all incidents displayed on the page. | |
Select all in all pages | Selects all incidents displayed on all pages. | |
Go to page | Specifies which page of the incident list to display. | |
Arrow buttons | Click to browse through pages. | |
Actions | Add Comment | Active when at least one incident is selected. Opens a text box for comments of up to 500 characters. |
Email Selected Events | Opens an email set-up window to send selected events. | |
Export Selected Events | Opens an export target path set-up window to send selected events. | |
Export device information to CSV (Data in-use/motion list only) | Exports the device parameters of selected incidents to a CSV file and displays the file name as a link. Displays an error message if the incident is not a device incident. | |
Release Redaction | Opens an authorization dialog box for entering user name and password. | |
Set Properties | Opens a dialog box that allows editing of properties (Severity, Status, and so forth) for all selected incidents. | |
Stakeholders | Allows the administrator to add a stakeholder to the selected incidents. Stakeholders receive an email notification every time an incident is modified. | |
Case Management | Allows the user to choose between adding the incidents to an existing case or creating a new case. | |
Labels | Opens dialog boxes to attach, detach, or delete labels. | |
View | Same operations as the View field, above. Allows the user to customize the list view. Columns can be rearranged, displayed, or hidden. The view can be saved as a named view, with options for Save group by, Save time filter, and Save column filter. Saved views can be public or private. | |
Filter | Allows filters to be edited, saved, deleted, or exported to Incident Tasks. Filter → Edit opens the Edit Filter Criteria page for selection and definition of filter parameters. | |
Create Device Template (Data in-use/motion list only) | Select a device and create a template based on the incident device information. Displays an error message if the selected template type does not match the incident device type. |