Use case: Find and review incidents related to printing sensitive data

Prev Next

You can filter incidents based on their severity, status, resolution, incident type, classification, user, rule set or where the incident was detected. You can then add or remove a reviewer to more than one incident to save time.

You must set up ePO - SaaS roles or users to be able to add a reviewer. In Trellix ePO MenuConfigurationsUsers & Roles, create a User or Role to appear in the User Catalog pane.

  1. In ePO - SaaS select MenuProtection Workspace.

  2. Click the incidents in Data Protection Overview to open the incident management workspace.

  3. Select the checkboxes of the criteria you want to filter incidents by in the Filter By pane. You can select as many of the criteria as you want to narrow your search.

  4. To find a printer incident, open the Incident Type section. If there are no Printer incidents, it will not be displayed.

  5. Select the checkboxes of the incidents you want to add a reviewer to in the Incidents pane. You can also hold down the Control key to select multiple checkboxes. The printer name is displayed in the Destination column in the table.

  6. Click Add from catalog in the Incident Details pane.

    The User Catalog pane opens.

  7. Select the user you want to add as a reviewer by clicking the plus symbol next to their email address in the User Catalog pane.

    You must create a user or role to appear in the User Catalog. To do this, go to ePO - SaaS MenuConfigurationUsers & Roles.

    The user will be listed as a Reviewer in the Incident Details pane.

  8. Click Save to confirm.

  9. Click Save in the dialog box to confirm you want to add the user as a reviewer to the selected incidents.