Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a Data Loss Prevention Incident Response SLA trigger

Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.

Before you begin

Role required:

  • sn_dlir.admin - Create, update, and delete DLP SLA triggers
  • sn_dlir.analyst.read - Read Trigger table.

Procedure

  1. Navigate to All > DLP Administration > SLA Triggers.

  2. Select New to create the SLA trigger.

    FieldDescription
    NameName of the trigger
    OrderOrder in which the trigger is considered.
    ActiveOption to evaluate the SLA trigger.
    Trigger when a DLP incident is updatedOption to evaluate the trigger condition on each update of the DLP incident.
  3. Configure a condition by selecting the rule record and defining conditions in the Trigger Condition field.

    For example, the trigger condition to set SLAs on DLP incidents from an email scan source would be [Scan Source][is][Email SMTP].

  4. Select Submit.

Result

Once a task SLA record for a Data Loss Prevention Incident Response incident is created, the SLA records tab becomes visible for that particular incident in the workspace. This tab enables you to use an SLA system for your organization's task.

Parent Topic:DLP Incident Response Administration

Related topics

DLP default configuration settings

Create end user lookup rules

Create assignment rules

Create incident consolidation rules

Create response due date rules

Create Approval Rules

Create user instructions templates

Create email templates

Create a Data Loss Prevention Incident Response SLA definition

Create assessments

Configure response option for your DLP incidents

Create incident response option rules

Create age chart configurations

Create user delegate configurations

Create repeat offender identification rules

Create additional incident data fields

DLP SLA Definition form

Configure advanced settings

Monitor DLP Integration Run process

DLP Incident Access Restrictions

DLP Incidents Archival