Using the Protection Workspace to manage incidents

Prev Next

The Data Protection Overview in Protection Workspace provides a visual representation of your data protection incidents reported by Trellix DLP – SaaS, which includes Trellix DLP Endpoint - SaaS, Trellix DLP Discover – SaaS, Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS.

It allows you to identify the incidents that do not comply with your organization's policy, and to locate significant violations quickly and efficiently by filtering how incidents are displayed. You can view an incident's status, investigate it, and prevent data loss, all from a single location. Incident management is carried out in Protection Workspace.

Protection Workspace displays incidents raised in your network over the past seven days by default. The incidents are displayed based on their severity. You can click the number of incidents or on the type of incidents to see the list of incidents. Click one of the bars of the graph to see the incidents generated on that day. The drop-down allows you to choose between incidents generated by Trellix DLP Endpoint - SaaS, Trellix Device Control,Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS (Data in use/Motion), Endpoint Discovery (Data at Rest (Local)), and Trellix DLP Discover – SaaS (Data at Rest (Shared)).

The incident management workspace in Protection Workspace is divided into several panes to more easily manage incidents:

Filter By — Filter incidents by their severity, status, resolution, the incident type, the user who triggered the incident, the classification criteria that is identified when a rule is triggered, the user logged in when the incident was generated, and the rule set.

Incidents — View all incidents, the details of individual incidents, and search for an incident.

Incident Details — View details about an individual incident and change its status, severity, resolution, or assign a reviewer. You can further manage incidents from the additional panes that open to the right of the Incident Details pane when you click to take an action.