View incident details

Prev Next

You can see more details about an incident that is detected when a rule is triggered.

  1. In ePO - SaaS Protection Workspace, click the incidents in the Data Protection Overview section to open the incident management workspace.

  2. Search for and select an incident by using the filters.

    Based on the filter and the search criteria you have selected, the Incidents pane displays the list of incidents.

  3. Hover over the incident for which you want to see the details. Select the checkbox to see more details about the selected incident.

    The Incident Details pane opens on the right. You can expand or collapse the panes side-ways.

  4. The first section in the Incident Details pane shows the general information about an incident. You can change the severity, status, resolution, and assign a reviewer.

  5. To view or update additional information, perform any of these actions:

    • To view additional information, such as URL details and the device details, expand the Additional Information section.

    • To view details of evidence files, expand the Evidence section and select a file name.

    • To view the justification information, such as justification option, text, and selected action, expand the Justification section. The Justification section will not appear if there is no justification information associated with the incident.

    • To view policy and rules that triggered the incident, expand the Policy and Rules section.

    • To view classifications, expand the Classifications section. The Classifications section is grayed out and the count is zero when the incident is not triggered by a classification rule.

    • To view collaborators, expand the Collaboration section. The Collaboration section only appears for incidents detected by Skyhigh Security Cloud.

  6. To email the incident details, select Email Incident from the three dots menu in the Incident Details pane.

  7. Click Save to save any updates to the incident details.