Incidents and operational events

Prev Next

There are different tools available to view incidents and operational events.

  • Incidents — The DLP Incident Manager module displays incidents generated from rules. Trellix DLP Endpoint, Trellix Device Control, Trellix DLP Network Prevent, Trellix DLP Network Monitor, Cloud DLP, and Skyhigh Security Cloud enforce rules and send incidents to DLP Incident Manager.

  • Operational events — The DLP Operations module displays errors and administrative information. Trellix DLP Discover, Trellix DLP Endpoint, and Trellix DLP Network Prevent send events to DLP Operations.

  • Cases — The DLP Case Management module contains cases that have been created to group and manage related incidents.

When multiple Trellix DLP products are installed, the consoles display incidents and events from all products.

The display for both DLP Incident Manager and DLP Operations can include information about the computer and logged-on user generating the incident/event, client version, operating system, and other information.

You can define custom status and resolution definitions. The definition consists of a custom name and color code, and can have the status of enabled or disabled. Custom definitions must be added and enabled in DLP Settings on the Incident Manager, Operations Center, or Case Management page before they can be used.

Logging events with Syslog

  • You can send certain events using the Syslog protocol to a Syslog server. Configure the Syslog server in the Windows Client configuration on the Debugging and Logging page. The events are sent whether rules are configured to trigger the events or not. The following actions are sent automatically when Send DLP Syslog events to Syslog server is enabled:

    • Printing

    • Copy to removable storage

    • Uploading a file to the web

    • Uploading a file to the cloud

    • Sending email

    • Connect or disconnect a plug and play device

    • Connect or disconnect a removable storage device

Stakeholders

A stakeholder is anyone with an interest in a particular incident, event, or case. Typical stakeholders are DLP administrators, case reviewers, managers, or users with incidents. Trellix DLP sends automatic emails to stakeholders when an incident, event, or case is created or changed. It can also automatically add stakeholders to the list, for example, when a reviewer is assigned to a case. The administrator also can manually add stakeholders to specific incidents, events, or cases.

Automatic email details are set in DLP Settings. Options on the Incident Manager, Operations Center, and Case Management pages determine whether automatic emails are sent, and who is automatically added to the stakeholders list. The administrator can add stakeholders manually from the DLP Incident Manager, DLP Operations, or DLP Case Management modules.