View incident details

Prev Next

View the information related to an incident.

For details about product features, usage, and best practices, click ? or Help.

  1. In ePO - On-prem, select DLP Incident Manager.

  2. From the Present drop-down list, select the option for your product.

  3. Click an Incident ID.

    The page displays general details and source information. Depending on the incident type you select, destination or device details are displayed.

    The page displays general details about the incident.

  4. To view additional information, perform any of these actions.

    • To view user information for incidents, click the user name in the Source area.

    • To view evidence files, click the Evidence tab and select a file name. The Evidence tab displays the Short and Unique Match String, Match Count, and Path of the embedded file that triggered the scan.

    • To view rules that triggered the incident, click the Rules tab.

    • To view classifications, click the Classifications tab.

      Note

      The Classifications tab does not appear for some incident types.

    • To view incident history, click the Audit Logs tab.

    • To view comments added to the incident, click the Comments tab.

    • To email the incident details, including decrypted evidence and hit highlight files, select ActionsEmail Selected Events.

    • To return to the incident manager, click OK.