Trellix DLP pulls incidents periodically from Skyhigh Security Cloud and displays them in the DLP Incident Manager. To manually import incidents Skyhigh Security Cloud, you can run the DLP Import Skyhigh Security Cloud Events Task server task.
Configure number of incidents in Skyhigh Security Cloud Server.
In ePO - On-prem, select Menu → Data Protection → DLP Settings → Skyhigh Security Cloud Server.
Select Connect to Skyhigh Security Cloud to enable the fields needed to configure the settings for Skyhigh Security Cloud incidents and policies.
Provide the Skyhigh Security Cloud server details and credentials.
To Pull incidents from Skyhigh Security Cloud, select the number of incidents that you want to import in a server task.
Note
The default number of incidents that you can import from Skyhigh Security Cloud is 1000.
To Push DLP policy to Skyhigh Security Cloud, select the policy name.
Run the server task to import Skyhigh Security Cloud incidents.
In ePO - On-prem, select Menu → Automation → Server Tasks.
Select the checkbox next to DLP Import Skyhigh Security Cloud Events, then select Actions → Run.
After the server task is complete, the specified number of incidents can be viewed in DLP Incident Manager.