Incident List page

Prev Next

This page provides administrators with a list of events triggered by policy rules. The list can be filtered for easier viewing.

The Incident List displays only policy violations. Administrative events such as agent updates are displayed in a separate console, DLP Operational Events.

Option definitions for the Present drop-down list

Option

Definition

Data-in-use/motion

Displays Trellix DLP Endpoint, Trellix Device Control, Trellix DLP Network Monitor, or Trellix DLP Network Prevent data. The Reporting Product column identifies which product produced the incident.

Data-at-rest (Endpoint)

Displays Trellix DLP Endpoint discover data

Data-at-rest (Network)

Displays Trellix DLP Discover data



Note

Only options for installed software are displayed.

Option definitions for data-in use/motion and data at rest (endpoint)

Category

Option

Definition

Menu bar

View

Drop-down list to display the view. Use Edit to create a view. The view can alternately be applied and switched off during the current session. Use Save to use a view between sessions.

Time (Trellix DLP Endpoint only)

Drop-down list to display the time filter.

Scan (Trellix DLP Discover only)

Opens the Select scan and run page to specify the scan and scan instance to display results for.

Filter

Drop-down list to select the display filter. Use Edit to create a filter. The available properties vary according to the Present setting. The filter can alternately be applied and switched off during the current session. Use Save to use a filter between sessions.

Group by

Drop-down list to organize data. The available filters vary according to the Present setting.

Search

Text box for searching the data.

Incident display area

Incident list

Displays incidents based on the current selections.

Tip

To add or remove columns, click Edit next to the View drop-down list.

Select all in this page

Selects all incidents displayed on the page.

Select all in all pages

Selects all incidents displayed on all pages.

Go to page

Specifies which page of the incident list to display.

Arrow buttons

Click to browse through pages.

Actions

Add Comment

Active when at least one incident is selected. Opens a text box for comments of up to 500 characters.

Email Selected Events

Opens an email set-up window to send selected events.

Export Selected Events

Opens an export target path set-up window to send selected events.

Export device information to CSV

(Data in-use/motion list only)

Exports the device parameters of selected incidents to a CSV file and displays the file name as a link. Displays an error message if the incident is not a device incident.

Release Redaction

Opens an authorization dialog box for entering user name and password.

Set Properties

Opens a dialog box that allows editing of properties (Severity, Status, and so forth) for all selected incidents.

Stakeholders

Allows the administrator to add a stakeholder to the selected incidents. Stakeholders receive an email notification every time an incident is modified.

Case Management

Allows the user to choose between adding the incidents to an existing case or creating a new case.

Labels

Opens dialog boxes to attach, detach, or delete labels.

View

Same operations as the View field, above.

Allows the user to customize the list view. Columns can be rearranged, displayed, or hidden. The view can be saved as a named view, with options for Save group by, Save time filter, and Save column filter. Saved views can be public or private.

Filter

Allows filters to be edited, saved, deleted, or exported to Incident Tasks. FilterEdit opens the Edit Filter Criteria page for selection and definition of filter parameters.

Create Device Template

(Data in-use/motion list only)

Select a device and create a template based on the incident device information. Displays an error message if the selected template type does not match the incident device type.