Operational events provides administrators with a list of administrative events such as policy changes or deployments. Events from Trellix DLP Endpoint and Trellix DLP Discover are listed, if both products are installed. The list can be filtered for easier viewing.
The DLP Operations console displays all administrative events connected with Trellix DLP Endpoint operation, such as policy changes, files being quarantined, or users logging on to Safe Mode. Events triggered by policy violations are displayed in a separate console, DLP Incident Manager.
Category | Option | Definition |
|---|---|---|
Menu bar | View | Drop-down list to display the view. Use Edit to create a view. The view can alternately be applied and switched off during the current session. Use Save to use a view between sessions. |
Time | Drop-down list to display the time filter. | |
Filter | Drop-down list to select the display filter. Use Edit to create a filter. The filter can alternately be applied and switched off during the current session. Use Save to use a filter between sessions. | |
Group by | Drop-down list to organize data. | |
Event display area | Event list | Displays events based on the current selections.
|
Select all in this page | Selects all events displayed on the page. | |
Select all in all pages | Selects all events displayed on all pages. | |
Go to page | Specifies which page of the event list to display. | |
Arrow buttons | Click to browse through pages. | |
Actions | Add Comment | Opens a text window to add a comment. Maximum comment length is 500 characters. |
Email Selected Events | Opens an email set-up window to send selected events. | |
Set Properties | Opens a dialog box that allows editing of properties (Severity, Status, and so forth) for all selected incidents. | |
Stakeholders | Allows the administrator to add a stakeholder to the selected events. | |
Labels | Opens a window to attach or detach labels to the event. You can also delete labels from the database, which detaches them from all events. | |
View | Same operations as the View field. | |
Filter | Same operations as the Filter field. Also allows you to export the current filter to an operational events task. |