Use the DLP Incident Manager to update and manage incidents.
Email selected events
Note
To optimize system performance, Trellix DLP automatically purges incidents from the live incidents list table when a million incidents are reached (Default value is 1 million and can be configured up to 5 million). This is done by considering the oldest incidents and retaining incidents as it is in the Incidents Archive table. Incidents will be removed from the Incidents Archive table upon configuring the DLP Purge History of Operational Events and Incidents task only, .
Use the Incident List for viewing real-time information related to an incident. Purged incidents continue to be displayed on the Incident History page. Use the ePO - On-prem DLP Purge History of Operational Events and Incidents and DLP purge evidences Server Tasks to mark evidence files for deletion and delete events and incidents from the history database tables.
If you have email notifications configured, an email is sent when an incident is updated.
The following tables give some details about the email and export selected events options.
Parameter | Value |
|---|---|
Maximum number of events to mail | 100 |
Maximum size of each event | unlimited |
Maximum size of the compressed (ZIP) file | 20 MB |
From | limited to 100 characters |
To, Cc, Bcc | limited to 500 characters |
Subject | limited to 150 characters |
Body | limited to 1000 characters |
Parameter | Value |
|---|---|
Maximum number of events to export | 1000 |
Maximum size of each event | unlimited |
Maximum size of the export compressed (ZIP) file | unlimited |