Managing incidents

Prev Next

Use the DLP Incident Manager to update and manage incidents.

Email selected events

Note

To optimize system performance, Trellix DLP automatically purges incidents from the live incidents list table when a million incidents are reached (Default value is 1 million and can be configured up to 5 million). This is done by considering the oldest incidents and retaining incidents as it is in the Incidents Archive table. Incidents will be removed from the Incidents Archive table upon configuring the DLP Purge History of Operational Events and Incidents task only, .

Use the Incident List for viewing real-time information related to an incident. Purged incidents continue to be displayed on the Incident History page. Use the ePO - On-prem DLP Purge History of Operational Events and Incidents and DLP purge evidences Server Tasks to mark evidence files for deletion and delete events and incidents from the history database tables.

If you have email notifications configured, an email is sent when an incident is updated.

The following tables give some details about the email and export selected events options.

Email selected events

Parameter

Value

Maximum number of events to mail

100

Maximum size of each event

unlimited

Maximum size of the compressed (ZIP) file

20 MB

From

limited to 100 characters

To, Cc, Bcc

limited to 500 characters

Subject

limited to 150 characters

Body

limited to 1000 characters



Export selected events

Parameter

Value

Maximum number of events to export

1000

Maximum size of each event

unlimited

Maximum size of the export compressed (ZIP) file

unlimited