Use case: Import Skyhigh Security Cloud incidents to Trellix DLP

Prev Next

Trellix DLP pulls incidents periodically from Skyhigh Security Cloud and displays them in the DLP Incident Manager. To manually import incidents Skyhigh Security Cloud, you can run the DLP Import Skyhigh Security Cloud Events Task server task.

  1. Configure number of incidents in Skyhigh Security Cloud Server.

    1. In ePO - On-prem, select MenuData ProtectionDLP SettingsSkyhigh Security Cloud Server.

    2. Select Connect to Skyhigh Security Cloud to enable the fields needed to configure the settings for Skyhigh Security Cloud incidents and policies.

    3. Provide the Skyhigh Security Cloud server details and credentials.

    4. To Pull incidents from Skyhigh Security Cloud, select the number of incidents that you want to import in a server task.

      Note

      The default number of incidents that you can import from Skyhigh Security Cloud is 1000.

    5. To Push DLP policy to Skyhigh Security Cloud, select the policy name.

  2. Run the server task to import Skyhigh Security Cloud incidents.

    1. In ePO - On-prem, select MenuAutomation Server Tasks.

    2. Select the checkbox next to DLP Import Skyhigh Security Cloud Events, then select ActionsRun.

After the server task is complete, the specified number of incidents can be viewed in DLP Incident Manager.