The Events API provides read access to threat events available in ePO - SaaS. This API provides limited details or summary of DLP incidents. You can see the detailed DLP incident information in Incident Details page.
Note
REST API calls to query and update Trellix DLP – SaaS incident details are not currently supported.
Get
/api/v2/eventsAPI for external clients to query threat events.Note
You can query for threat events if you are using Trellix Endpoint.