Reviewing and managing incidents to fine-tune your policies

Prev Next

You can review, analyze, and manage incidents for policy violations that have occurred. These functions include:

  • Incident management — Incidents are sent to the ePO - On-prem Event Parser and stored in a database. Incidents contain the details about the violation, and can optionally include evidence information. You can view incidents and evidence as they are received in the DLP Incident Manager console.

  • Case management — Group-related incidents into cases for further review in the DLP Case Management console.

  • Evidence collection — For rules that are configured to collect evidence, a copy of the data or file is saved and linked to the specific incident. This information can help determine the severity or exposure of the event. Evidence is encrypted using the AES-256 algorithm before being saved.

  • Hit highlighting — Evidence can be saved with highlighting of the text that caused the incident. Highlighted evidence is stored as a separate encrypted HTML file.

  • Reports — Reports, charts, and trends are created in ePO - On-prem dashboards.