These are a list of filters you can use to search within the incident management workspace.
Filter name | |
All Recipients | Incident ID |
Application | IP |
Bcc | Matched Recipients |
Cc | Matched URL |
Classification | Network Share Path |
Destination Application | Printer Name |
Destination Application File Name | Reviewer |
Destination IP | Rule |
Destination Path | Sender |
Destination Templates | Source IP |
Device | Source Path |
Device Class | Subject |
Device Description | To |
Device Name | Unique Match Strings |
Event ID | User |
Evidence Name | Volume Label |
Evidence Path | Web Request URL |
Note
The Event ID filter corresponds to the event "autoguid" in the Trellix DLP Endpoint - SaaS Incidents API.