Use case: Configure email notifications to receive alerts when an incident or operational event is generated

Prev Next

You can set up email notifications for incidents and operational events. Any update to an incident or operational event sends an email notification that includes a link to the incident details page in Incident Manager.

  • Create reviewers to assign to an incident or operational event. You can either set a reviewer from Incident Manager or Operational Event Manager.

The process to add email notifications is similar for DLP Incident Manager and DLP Operations.

  1. Configure your email server settings in ePO - On-prem:

    1. In ePO - On-prem, go to MenuConfigurationServer SettingsEmail Server.

    2. Click Edit and provide the SMTP server name, server port, authentication, and the email address from where the emails are sent.

      The ePO - On-prem DNS server name is used as the link in the incident notification email. You can provide host names (internaldomain.com), fully qualified domain names (FQDN) (server1.internaldomain.com ), or IP addresses. To change the default DNS name to a different format:

      • In ePO - On-prem, go to MenuConfigurationServer SettingsTrellix ePO Server Public DNS.

      • Click Edit and specify the name of the email server that sends the emails.

        Note

        When you provide the server name in the FQDN format, the link in the incident email takes you directly to the incident in Incident Manager without having to relogin to the server.

        Example of an incident link with the FQDN server name
        Example of an incident link with the FQDN server name


  2. Create email notifications:

    1. In ePO - On-prem, select MenuData ProtectionDLP Incident Manager or MenuData ProtectionDLP Operations.

    2. Select Incident Tasks or Operational Event Tasks, then select Automatic mail Notification.

      If you chose Incident Tasks, you must also select the type of incident, such as Data-in-use/motion.

    3. Click ActionsNew Rule and enter a name and optional description.

      Rules are enabled by default. You can change this setting to delay running the rule.

    4. Select which events you want to process, then specify Recipients, Subject, and Body.

      Except for Body, these fields are needed. You can insert variables from the drop-down list as needed.

    5. Add the email body text.

    6. (Optional for DLP Incident Manager) Select the checkbox to attach evidence information to the email.

    7. Click Next to add the rule criteria and their Comparison and Value parameters, then click Save.

The ePO - On-prem server name is registered and email notifications are sent when an incident or operational event is updated.