Managing incidents within Protection Workspace

Prev Next

You can use the incident management workspace to review and manage policy violation incidents. Create or use predefined filters to change what is displayed to find the incidents you want to manage more easily.

The Protection Workspace also works with ePO - SaaS Queries & Reports to create Trellix DLP – SaaS reports, and display data on ePO - SaaS dashboards.

Operations you can perform on incidents include:

  • Assign reviewer — Assign a reviewer to incidents.

  • Download incident details — Download a .zip file of incident details to the browser.

  • Email incident — Email incident details

  • Update properties — Edit the severity, status, or resolution; or assign a user or group as a reviewer.

Incidents generated by Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS are displayed by selecting DLP Network Prevent or DLP Network Monitor in the Detected By filter.

Incidents generated in Security Cloud , and those generated by Skyhigh Secure Web Gateway (SWG) for Cloud Service, are displayed in the incident management workspace, but can't be modified in ePO - SaaS.

You can find these incidents by selecting Skyhigh Security Cloud, or Shadow/Web DLP for Skyhigh Secure Web Gateway (SWG) for Cloud Service incidents, in the Detected By filter. You can download or email these incidents, but to update them you must use the Skyhigh Security Cloud Policy Incidents page.