Create additional incident data fields
Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.
Before you begin
Role required:
- sn_dlir.admin
- sn_dlir.analyst and sn_dlir.analyst_read
Important: Additional incident data fields for DLP incidents are supported only on the San Diego version or later.
About this task
Additional Incident Data Fields are not stored as columns on the DLP incident table. Unlike standard table-level fields, they cannot be queried directly through list views, reports, or scripts that reference incident table fields.
Additional Incident Data Fields view differs by role. DLP Analysts can view and set field values in the DLP Ops portal. DLP End Users can set field values, but fields that contain no value are hidden from them in the DLP Workspace. For example, an unchecked Check box or a Choice field with no selection is not displayed to end users.
Procedure
Navigate to All > DLP Administration > Additional Incident Data Fields.
Create an Additional Incident Data Fields by clicking New.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Name | Name of the Additional Incident Data Fields. |
| Type | Option to select the type of Additional Incident Data Fields. You can choose one of the following types:- String - Number - Check box - Choice If you select the Additional Incident Data Fields type as Choice, then after creating the Additional Incident Data Fields you can define the Additional Incident Data Fields choice options. To create an Additional Incident Data Fields choice option:
|
| Order | Option to choose the order in which the Additional Incident Data Fields should be displayed. You can define the order value for each Additional Incident Data Fields. The Additional Incident Data Fields are sorted based on the order values that you define.By default, the Additional Incident Data Fields are sorted in ascending order. You can sort the Additional Incident Data Fields in descending order by clicking on the Order column. |
| Active | Option to indicate whether the Additional Incident Data Fields is active. |
| Description | Description for the Additional Incident Data Fields you created. |
- Select Submit.
Parent Topic:DLP Incident Response Administration
Related topics
DLP default configuration settings
Create incident consolidation rules
Create response due date rules
Create user instructions templates
Create a Data Loss Prevention Incident Response SLA trigger
Create a Data Loss Prevention Incident Response SLA definition
Configure response option for your DLP incidents
Create incident response option rules
Create age chart configurations
Create user delegate configurations
Create repeat offender identification rules
Monitor DLP Integration Run process