Trellix DLP products divide events into two classes: incidents (that is, policy violations) and administrative events. These events are viewed in the two consoles, DLP Incident Manager and DLP Operations.
When a Trellix DLP product determines a policy violation has occurred, it generates an event and sends it to the ePO - On-prem Event Parser. These events are viewed, filtered, and sorted in the DLP Incident Manager console, allowing security officers or administrators to view events and respond quickly. If applicable, suspicious content is attached as evidence to the event.
As Trellix DLP products take a major role in an enterprise’s effort to comply with all regulation and privacy laws, the DLP Incident Manager presents information about the transmission of sensitive data in an accurate and flexible way. Auditors, signing officers, privacy officials and other key workers can use the DLP Incident Manager to observe suspicious or unauthorized activities and act in accordance with enterprise privacy policy, relevant regulations or other laws.
The system administrator or the security officer can follow administrative events regarding agents and policy distribution status.
Based on which Trellix DLP products you use, the DLP Operations console can display errors, policy changes, agent overrides, and other administrative events.
You can configure an email notification to be sent to specified addresses whenever updates are made to incidents, cases, and operational events.