Reviewing and managing incidents to fine-tune your policies

Prev Next

You can review, analyze, and manage incidents for policy violations that have occurred. These functions include:

  • Incident management — Incidents are displayed in the incident management workspace within the Protection Workspace. Incidents contain the details about the violation, and can optionally include evidence information.

  • Operational events — View errors and administrative events in the Operational Event Management console.

  • Evidence collection— Your evidence files and match highlights are stored using Amazon S3. For more information about storing evidence files on Amazon S3, see Storing evidence and fingerprint files topic in theTrellix DLP Endpoint - SaaS, Trellix DLP Network Prevent – SaaS, or Trellix DLP Network Monitor – SaaSInstallation Guide.

  • Hit highlighting — Evidence can be saved with highlighting of the text that caused the incident. Highlighted evidence is stored as a separate encrypted HTML file.

  • Reports — Reports, charts, and trends are created in ePO - SaaS dashboards.