Incident Manager settings page

Prev Next

Use this page to specify the Incident Manager settings.

Option definitions

Option

Definition

Last Modified

Displays the date and time stamp of the last changes to the settings.

Automatic Email Notifications

When selected, all stakeholders receive an email notification when an incident is changed. Use the Stakeholders checkboxes to add reviewers or users to the stakeholder list.

Short Match String

Configures storage of short match string and unique match list data in the ePO - On-prem database as encrypted or clear text.

Incident Management

Use the options to determine whether product vectors are displayed in the incident list.

Redaction Fields

Choose specific fields for redaction (relevant when Obfuscate sensitive incidents data permission is activated).

Note

The Source field is applicable only to Removable Storage Protection rules. Select the Source field to hide the location of the file from where it is copied to the removable storage media in the incident details.

Status

Enable or disable status designations in the incident list. Built-in status can be:

  • New

  • Pending

  • Viewed

  • Under Investigation

  • Escalated

  • Resolved

  • False Positive

Resolution

Enable or disable resolution designations in the incident list. Built-in resolution can be:

  • None

  • Case opened

  • Resolved - HR notified

  • Resolved - Manager notified

  • Resolved - User notified

  • Closed - Authorized

  • Closed Business workflow

  • Closed - False positive

  • Closed - test

ActionsAdd Status

Create a custom status definition.

ActionsAdd Resolution

Create a custom resolution definition.