When administrative events — such as policy changes, deployments, or errors — occur, an event is generated and sent to Operational Event Management. When multiple Trellix DLP – SaaS products are subscribed, the console displays operational events from all products.
Operational Event Management displays information about the event such as the date and time it occurred, the type of event, why the administrative task failed, its status, related files, and other information.
Use Operational Event Management to manage operational events and tasks. You can filter operational events by their status, the product that detected them, the event type, status, and resolution.
When you enter Operational Event Management, the Filter By and Events panes are open by default. New panes open on the right of each screen.
Prerequisites
Users must be assigned the Operational Event Manager permission set to view and manage operational events.
From the Trellix ePO - SaaS menu, click Users & Roles.
The Users & Roles page opens.
Select the user you want to assign Operational Event Management permissions to from the list of users.
Select the checkbox next to Operational Event Manager, then click the Save Changes button.
Managing an operational event
Operational Event Management displays details about an event when it is generated. You can update certain information for each event individually or as a group.
Search for and select an event using the Filter By option.
The Events pane displays the list of matching events based on the filters selected.
In the Events pane, click on the search box to narrow your search further. Click the search suggestion to add it as a filter to the list of events.
The Events pane displays a selection of the additional details available about the event. Select the checkbox to view more details.
The Event Details pane opens on the right. You can expand or collapse the pane sideways.
To view or update additional information, perform any of these actions:
To update the severity of an incident, select an option from the Severity drop-down list. You can change the status to Informational if you don't want to track the incident later.
To update the status of an incident, select an option from the Status drop-down list.
To update the resolution of an incident, select an option from the Resolution drop-down list.
Click Save to apply the changes.
View and download file errors associated with an event
Operational Event Management displays file errors generated by a scan, which you can then investigate further.
Search for and select an event by using the filters.
Based on the filters selected, the Events pane displays the list of matching events.
In the Events pane, click on the search box to narrow your search further. Click the search suggestion to add it as a filter to the list of events.
The Events pane displays a selection of the additional details available about the event. Select the checkbox to view more details.
The Event Details pane opens on the right. You can expand or collapse the pane sideways.
Click the File Errors section to view the file errors associated with the operational event. The errors are grouped by type. Click the error to see the errors related to that event.
The File Errors pane opens on the right.
Note
The list of file errors displayed is limited to 200 per type. The number of additional file errors identified is displayed in the File Errors section of the Event Details card.
Use the drop-down list in the File Errors pane to display file errors by type.
Click the download icon to download the file errors.
All file errors are downloaded as a UTF-8 encoded .csv file.