Incidents List
The Incidents list provides acts as a centralized repository for tracking and
managing all incidents that match the Incident Management filters you apply. It
plays a crucial role for maintaining an organized and effective approach to managing
your data security incidents.
For each incident, the DLP incidents list provides crucial information such as the
date and time the incident occurred, the Incident ID, the data profile containing
the sensitive match criteria, the asset name, the region where the incident
occurred, the user who generated the incident, the severity of the data security
incident, the security enforcement channel where the incident was generated, and
more. Additionally, you can configure the Incident list settings to hide or display
incident information as needed.
The Incident list updates in real time when new users generate new incidents to
ensure real-time visibility into incident management. Furthermore, all incidents
persist even after a data security administrator resolves the incident to maintain
an accurate historical record. This supports your data security administrators in
conducting postincident analysis and lessons learned activities.
Data security administrators can download (
) the full list of DLP incidents to their local device
in
.csv format based on the currently applied filters.
This enables your data security administrators to create workflows based on the
types of DLP incidents that matter most to your organization.