Viewing Incidents and Reportshttp://www.websense.com/content/support/library/data/v76/help/view incidents.aspx

TRITON - Data Security Help

Viewing Incidents and Reports

To view incidents and reports on incidents, select Main > Reporting > Data Loss Prevention or Discovery. Here you can view an incident list and details for individual incidents, or you can choose from a catalog of reports. Several built-in reports are provided. The ones you’ve viewed most recently are displayed on the main Reporting page in a section called Recent Reports. The order of these reports changes with use.

Listed below are the most common reports.

Note: What you can see depends on your permissions. See Setting reporting preferences for instructions on configuring settings for incidents and reports.

Report Catalog See a list of all the reports that are available, both built-in and user-defined.

Data loss prevention reports

Incidents (last 3 days) or (last 30 days) - View a list of all the incidents for the last 3 or 30 days. See detailed information on each incident. Investigate the violated policies and the actions taken by Websense software. Evaluate whether policy changes are needed. Select this report when you want to manage incident workflow, remediation, and escalation.

Dashboard (last 7 days) - This report provides an overview of information leaks in the system, what actions are being taken on them, which channels are problematic, and what kind of violations are being made.

Top Violated Policies (last 7 days) - Find out which policies were violated most frequently over the last 7 days. Assess the security risk to your organization.

All Violations by Severity & Action (last 7 days) - See incidents by the actions (permit, block, notify) and severities applied to them. Compare the ways Websense software enforces policies, and gain insight into potential policy changes.

Top Sources & Destinations (last 7 days) - Find out who are the top violators involved in data leakage and the top domains where sensitive data was posted. This report contains information from the last 7 days.

Incident Trends (this quarter) - View incident statistics for this quarter. Find out if the number of violations in your organization reduces over time.

Incident Status (last 7 days) - View the status of all incidents from the last 7 days.

Discovery reports

Incidents - View a list of recent incidents, with detailed information on each incident. Evaluate whether policy changes are needed. Select this report when you want to manage incident workflow, remediation, and escalation.

Sensitive data on file servers and SharePoint servers - Find out what vulnerable data was most violated and where it is stored. Assess the security risk to your organization.

Sensitive data in private mailboxes - Find out which policies were violated most, and in which mailboxes the violations occurred. Assess the security risk to your organization.

Sensitive data in databases - Find out which policies were violated most, and in which databases the violations are located. Assess the security risk to your organization.

Mailboxes with sensitive data - View which mailboxes contain sensitive data, and assess any violated policies in each mailbox.

Hosts with sensitive data - Find out which hosts contain sensitive information, and assess any violated policies on each host.

Databases with sensitive data - Find out which databases contain sensitive information, and assess any violated policies on each database.

Dashboard - Provides an at-a-glance view of system metrics for information leaks in the system and the actions being taken on them.

Click View Complete Document for more.