Arrange the way incidents appear based on attributes such as time, location, user, or severity.
For details about product features, usage, and best practices, click ? or Help.
In ePO - On-prem, select DLP Incident Manager.
From the Present drop-down list, select the option for your product.
Perform any of these tasks from the Incident List or the Incident History tabs.
To sort by column, click a column header.
To change columns to a custom view, from the View drop-down list, select a custom view.
To filter by time, from the Time drop-down list, select a time frame.
To apply a custom filter, from the Filter drop-down list, select a custom filter, or click Edit to create a filter.
Note
Available properties for filters are selected from a list of ePO - On-prem and Trellix DLP properties.
To group by attribute:
From the Group By drop-down list, select an attribute.
A list of available options appears. The list contains up to 250 of the most frequently occurring options.
Select an option from the list. Incidents that match the selection are displayed.
When working with Trellix DLP Endpoint incidents, select User ID to display the names of users that have triggered violations. Select a user name to display all incidents for that user.