You can filter the way incidents are displayed to locate significant policy violations based on attributes such as the severity, status, resolution, incident type, classification, user, or the rule set.
The incidents generated by Data Protection and Trellix Device Control, Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS rules are displayed under the Data In-Use / Motion category. Incidents generated by Trellix DLP Endpoint - SaaS Discovery rules are displayed under the Data at Rest (Local) category. Incidents generated by Trellix DLP Discover are displayed under the Data at Rest (Shared) category.
Incident filters.
Option | Definition | |
|---|---|---|
Filter By | Data In-Use / Motion Data at Rest (Local) | Filter the incidents by category. |
Severity type: Critical Major Minor Warning Informational | Filter the incidents by severity. | |
Status | Filter the incidents by current status | |
Resolution | Filter the incidents by resolution. | |
Incident type | Filter the incidents based on the device in which the incident has occurred. | |
Classification | Filter the incidents based on classification criteria that has been identified. | |
Detected By | Filter the incidents based on the product that detected them. | |
Users | Filter the incidents based on the user who triggered the incident. | |
Rule Set | Filter the incidents based on the rule set triggered. |
Option | Definition | |
|---|---|---|
Filter By | Data at Rest (Shared) | Filter the incidents by category |
Severity | Filter the incidents by severity | |
Scan Name | Filter the incidents by the name of the scan | |
Status | Filter the incidents by current status | |
Repository Name | Filter the incidents based on the repository scanned | |
Classification | Filter the incidents on the classification criteria identified | |
Rule Set | Filter the incidents based on the rule set triggered |