Incidents List
The Incidents list acts as a centralized repository for tracking and managing all
incidents that match the Incident Management filters you apply. It plays a crucial
role in maintaining an organized and effective approach to managing your data
security incidents.
For each incident, the DLP incidents list provides crucial information such as the
date and time the incident occurred, the Incident ID, the data profile containing
the sensitive match criteria, the asset name, the region where the incident
occurred, the user who generated the incident, the severity of the data security
incident, the security enforcement channel where the incident was generated, and
more. Additionally, you can configure the Incident list settings to hide or display
incident information as needed.
The Incident list updates in real time when new users generate new incidents to
ensure real-time visibility into incident management. Furthermore, all incidents
persist even after you resolve them to maintain an accurate historical record. This
supports postincident analysis and lessons learned activities.
You can download (
) the full list of DLP incidents to your local device
in
.csv format based on the currently applied filters.
This enables you to create workflows based on the types of DLP incidents that matter
most to your organization.