When Trellix DLP receives data that matches parameters defined in a rule, a violation is triggered and Trellix DLP generates an incident.
Using the DLP Incident Manager in ePO - On-prem, you can view, sort, group, and filter incidents to find important violations. You can view details of incidents or delete incidents that are not useful.
Device plug incidents
Two options on the Incident List Actions menu allow you to work with device plug incidents. Create Device Template creates a device definition from a device plug incident. The option is available only when a single device plug incident is selected. If you select more than one incident, or a non-device plug incident, a popup informs you of your error. Export Device Information to CSV saves information from one or more device plug incidents. You can import saved device information from the DLP Policy Manager → Definitions → Device Templates page.