Focus
Focus
Table of Contents

Filter Incidents

Learn how to use filter options on Data Security to investigate incidents identified based on your policy rules.
Filters help you efficiently assess incidents identified based on your policies. Use the filters provided to view the information from different vantage points; for example, you can search by Owner to see all the incidents for a particular asset owner.
  1. Select Data SecurityIncidents to view incidents.
  2. Select your desired filter options.
    Filter
    Description
    Status
    Status, which includes both open and closed states.
    Date Found
    Time frame or specific date on which the incident was discovered.
    Cloud App
    Cloud application on which the incidents were discovered.
    Rule
    Policy rules that underly the violations.
    Assigned To
    Administrator to which incidents are assigned.
    Owners
    User that owns the asset associated with the incident. String matches on Name, Email, and Email Domain for People. Displays results only if the user has Owned Items.
    Data Security does not limit the number of owners you can select, but your browser cannot load pages (URLs) that exceed 2,047-2,083 characters, depending on your browser.
    Last Activity
    Time frame or specific date of last change to the asset.