Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Filter tab
Administrator Help | Forcepoint DLP | Version 8.5.x
Related topics:
Use the Filter tab of the Report Catalog > Edit Report page to focus the report on the data that is most relevant to you. For example, apply the Action filter and display only incidents with the action Block. Apply as many filters as needed.
For each filter to apply:
1.
Select the filters in the Filter by pane on the left.
2.
Select Enable filter in the properties pane.
3.
The filters that are available vary depending on the type of report. Filters and their properties are described below.
*
*
*
Data Loss Prevention filters
 
Filter incidents by the person to whom they are assigned. Unassigned displays all incidents that have not been assigned to any administrator. Because filters can be available for all administrators, checking the Assigned to current administrator check box displays incidents assigned to the administrator who is currently logged onto the Security Manager. Assigned to selected administrators enables you to select specific administrators whose assigned incidents you want to display.
Select CASB Service to view incidents detected when users synced or shared files with cloud applications such as Microsoft OneDrive for Business or Box. (Enable the CASB Service on the Settings > General > Service page.)
Click Edit to add or remove content classifiers to the filter, then select a threshold for each.
Select Enable filter to select destinations from your resource list or enter them as free text. Choose which method you want to use from the drop-down list. If your free text includes a comma, enclose the value in quotes. For example: "Doe, John".
See Selecting items to include or exclude in a policy for more details on using this selector.
*
Last n days - Select this option to display incidents from the last n days, then select the number of interest. For example, display incidents from the last 30 days.
*
Time period - Select this option to display incidents that transpired in a set period of time, then select the period. Example: last 24 hours, this week, or last month.
*
Exact date and time - Select this option to display incidents that transpired during a time period that you define, then select the From and To dates and times from the drop-down lists.
*
Entire day - Select Entire day to show all incidents during the date range, no matter what time of day they took place.
*
From ... to ... - Select this option to show only incidents from a specific period.
For example, if you select Last 60 days and From 8 a.m. to 5 p.m., the report displays all incidents from the last 60 days that were detected between 8 a.m. and 5 p.m.
*
Select Filter by date to specify the date and time of the actions that were taken. Only actions during this period are included in the report. Select a date range and time of day.
*
Select Filter by administrator to specify the administrator who performed the listed workflow action. Enter the administrator name or names. Separate multiple names by commas. For example: Type "jdoe, bsmith" to view incidents that jdoe and bsmith acted on.
*
Select Filter by details to specify details shown on the incident's History tab. Details are automatically added when a workflow action is taken, such as "incident assigned to jdoe." If administrators add comments to the incident (Workflow > Add Comments), those are appended to the workflow details.
Filter incidents by a previously-defined tag. (See Tagging incidents). Select the tags by which to filter the report and click Add. Continue until all required tags have been added.
*
Last n days - Select this option to display incidents from the last n days, then select the number of interest. For example, display incidents from the last 30 days.
*
Time period - Select this option to display incidents that transpired in a set period of time, then select the period. Example: last 24 hours, this week, or last month.
*
Exact date and time - Select this option to display incidents that transpired during a time period that you define, then select the From and To dates and times from the drop-down lists.
*
Entire day - Select Entire day to show all incidents during the date range, no matter what time of day they took place.
*
From ... to ... - Select this option to show only incidents from a specific period.
For example, if you select Last 60 days and From 8 a.m. to 5 p.m., the report displays all incidents from the last 60 days that were detected between 8 a.m. and 5 p.m.
Select the severity of incidents to display. Select High if you want to display incidents of high severity, and so on. Select as many severity levels as desired.
See Selecting items to include or exclude in a policy for more details on using this selector.
Mobile Device filters
 
Filter incidents by the person to whom they are assigned. Unassigned displays all incidents that have not been assigned to any administrator. Because filters can be available for all administrators, checking the Assigned to current administrator check box displays incidents assigned to the administrator who is currently logged onto the Forcepoint Security Manager. Assigned to selected administrators enables you to select specific administrators whose assigned incidents you want to display.
Click Edit to add or remove content classifiers to the filter, then select a threshold for each.
See Selecting items to include or exclude in a policy for more details on using this selector.
4.
Click Add.
*
Last n days - Select this option to display incidents from the last n days, then select the number of interest. For example, display incidents from the last 30 days.
*
Time period - Select this option to display incidents that transpired in a set period of time, then select the period. Example: last 24 hours, this week, or last month.
*
Exact date and time - Select this option to display incidents that transpired during a time period that you define, then select the From and To dates and times from the drop-down lists.
*
Entire day - Select Entire day to show all incidents during the date range, no matter what time of day they took place.
*
From ... to ... - Select this option to show only incidents from a specific period.
For example, if you select Last 60 days and From 8 a.m. to 5 p.m., the report displays all incidents from the last 60 days that were detected between 8 a.m. and 5 p.m.
*
Select Filter by date to specify the date and time of the actions that were taken. Only actions during this period are included in the report. Select a date range and time of day.
*
Select Filter by administrator to specify the administrator who performed the listed workflow action. Enter the administrator name or names. Separate multiple names by commas. For example: Type "jdoe, bsmith" to view incidents that jdoe and bsmith acted on.
*
Select Filter by details to specify details shown on the incident's History tab. Details are automatically added when a workflow action is taken, such as "incident assigned to jdoe." If administrators add comments to the incident (Workflow > Add Comments), those are appended to the workflow details.
Filter incidents by a previously-defined tag (see Tagging incidents). Select the tags by which to filter the report and click Add. Continue until all required tags have been added.
*
Last n days - Select this option to display incidents from the last n days, then select the number of interest. For example, display incidents from the last 30 days.
*
Time period - Select this option to display incidents that transpired in a set period of time, then select the period. Example: last 24 hours, this week, or last month.
*
Exact date and time - Select this option to display incidents that transpired during a time period that you define, then select the From and To dates and times from the drop-down lists.
*
Entire day - Select Entire day to show all incidents during the date range, no matter what time of day they took place.
*
From ... to ... - Select this option to show only incidents from a specific period.
For example, if you select Last 60 days and From 8 a.m. to 5 p.m., the report displays all incidents from the last 60 days that were detected between 8 a.m. and 5 p.m.
Select the severity of incidents to display. Select High to display incidents of high severity, and so on. Select as many severity levels as desired.
Discovery filters
 
Filter incidents by the person to whom they are assigned. Unassigned displays all incidents that have not been assigned to any administrator. Because filters can be available for all administrators, checking the Assigned to current administrator check box displays incidents assigned to the administrator who is currently logged onto the Forcepoint Security Manager. Assigned to selected administrators enables you to select specific administrators whose assigned incidents you want to display.
*
Last nn days - Select the number of days from the spinner.
*
Time period - Select the range from the drop-down list. Example: last 24 hours or this week.
*
Exact dates - Select the From and To dates from the drop-down lists.
*
Select Filter by date to specify the date and time of the actions that were taken. Only actions during this period are included in the report. Select a date range and time of day.
*
Select Filter by administrator to specify the administrator who performed the listed workflow action. Enter the administrator name or names. Separate multiple names by commas. For example: Type "jdoe, bsmith" to view incidents that jdoe and bsmith acted on.
*
Select Filter by details to specify details shown on the incident's History tab. Details are automatically added when a workflow action is taken, such as "incident assigned to jdoe." If administrators add comments to the incident (Workflow > Add Comments), those are appended to the workflow details.
Filter incidents by a previously-defined tag (see Tagging incidents). Select the tags by which to filter the report and click Add. Continue until all required tags have been added.
*
Show only locked incidents (and not unlocked incidents)
*
Exclude locked incidents (and show only unlocked incidents)
*
Select Private mailbox to display incidents from private mailboxes.
*
Select Public mailbox to display incidents from public mailboxes.
Select the severity of incidents to display. Select High to display incidents of high severity, and so on. Select as many severity levels as desired.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2017 Forcepoint. All rights reserved.