Purge Events/Rule page

Prev Next

The purge task is used to delete incidents from the events table in the DLP Incident Manager or DLP Operational Events based on defined criteria. Events purged from the incident or operational events list can be viewed on the history page. You can also create purge tasks for the history page. When you purge incident history, you also purge the evidence files associated with the incidents. Events purged from the history are lost forever.

Rule Properties

Rule properties option definitions

Option

Definition

Name

Task name. Required field, must be unique — duplicate names are flagged.

Description

Optional field for additional information.

State

Enabled or disabled. All tasks are enabled by default.



Rule Criteria

This page defines the criteria that trigger the email notification. The Available Properties list includes Trellix DLP properties and ePO - On-prem properties. You can select any combination of properties from the list.

Rule criteria option definitions

Option

Definition

Comparison

Select from the drop-down list. Available comparisons vary with the selected property.

Value

Available values vary with the selected property — some are text fields, some are drop-down lists, some require selecting a predefined definition.