Data Loss Prevention

 View Only
  • 1.  Incident Search - DLP

    Posted Dec 20, 2013 08:13 AM

    Dear All,

    Let me first clarify the criteria.

    My question is regarding Data Loss Prevention Tools.

    I would like to sort out the incident where I didn't added/put any incident notes.

    Can somebody help me, how can I make a Report of list of that incident in DLP where I have not added/put any notes.

    Please help if there is any filteration feature.

    Thanks.



  • 2.  RE: Incident Search - DLP

    Trusted Advisor
    Posted Dec 20, 2013 10:46 AM

    hello,

     

     if it is your note, you can a filter with "Incident history issuer" not contains "your dlp login". this will give you all incident without any note set by you.

     

     regards



  • 3.  RE: Incident Search - DLP

    Posted Dec 20, 2013 11:23 AM

    i agree with stephane



  • 4.  RE: Incident Search - DLP

    Posted Dec 23, 2013 06:51 AM

    This will not give the incident without note , it will just give u the incident on which any activity/event or status changed by Incident history issuer. But above idea may help some extent



  • 5.  RE: Incident Search - DLP

    Posted Dec 23, 2013 10:11 AM

    Dear All,

    Thanks for your valuable response.

    but above solutioned is not related to my question.

    IYes we can sort out incident list with the help of filter Incident history issuer.

    I want solution with incidents notes,

    can someone help me to sort out this issue.

    Is there any nul value that we can put in incident notes filter to search with null incident notes.?



  • 6.  RE: Incident Search - DLP
    Best Answer

    Trusted Advisor
    Posted Dec 23, 2013 10:23 AM

    hi,

     if you did not perform any action "history issuer" should work as when you add a note you are added in history audit trail. But if you are looking for all incident wher you did not set a note, but you have already performed some action like set a status or a severity so i agree it will not work.

     

     So if you want to check on incident note content, i am afraid you have to process it out of DLP. I did that for one of my customer, wher DLP stakeholders add specific note to tag incident and then my external script compute delay and SLA based on that in order to ensure process compliance.

     

     Regards



  • 7.  RE: Incident Search - DLP

    Posted Dec 26, 2013 04:13 AM

    Hi Lion Shaikh,

    One thing you can try as belown 

    You should add multiple criteria filters like incident history issuer and another filter as note contains- add some standard worrds, lines etc which you added in your most of incident note and filter out.



  • 8.  RE: Incident Search - DLP

    Posted Jan 19, 2014 04:38 AM

    Applying multiple filters is correct one.



  • 9.  RE: Incident Search - DLP

    Posted Feb 27, 2014 09:50 AM
    Thanks you stephane. Appreciate your co-operation.