Viewing incident filters

Prev Next

You can filter the way incidents are displayed to locate significant policy violations based on attributes such as the severity, status, resolution, incident type, classification, user, or the rule set.

The incidents generated by Data Protection and Trellix Device Control, Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS rules are displayed under the Data In-Use / Motion category. Incidents generated by Trellix DLP Endpoint - SaaS Discovery rules are displayed under the Data at Rest (Local) category. Incidents generated by Trellix DLP Discover are displayed under the Data at Rest (Shared) category.

Incident filters.

Option definitions to filter Data Protection, Device Control, DLP Endpoint Discovery, and incidents

Option

Definition

Filter By

Data In-Use / Motion

Data at Rest (Local)

Filter the incidents by category.

Severity type:

Critical

Major

Minor

Warning

Informational

Filter the incidents by severity.

Status

Filter the incidents by current status

Resolution

Filter the incidents by resolution.

Incident type

Filter the incidents based on the device in which the incident has occurred.

Classification

Filter the incidents based on classification criteria that has been identified.

Detected By

Filter the incidents based on the product that detected them.

Users

Filter the incidents based on the user who triggered the incident.

Rule Set

Filter the incidents based on the rule set triggered.



Option definitions to filter Trellix DLP Discover – SaaS incidents

Option

Definition

Filter By

Data at Rest (Shared)

Filter the incidents by category

Severity

Filter the incidents by severity

Scan Name

Filter the incidents by the name of the scan

Status

Filter the incidents by current status

Repository Name

Filter the incidents based on the repository scanned

Classification

Filter the incidents on the classification criteria identified

Rule Set

Filter the incidents based on the rule set triggered