cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Level 8
Report Inappropriate Content
Message 1 of 4

Permission sets for DLP

Jump to solution

Hello,

I would like to know if it is possible to allow a user to view only incidents related to a specific System Tree path.

In fact, I have several groups, and my goal is to allow each  reviewer group to view his events, but not all of others that doesn't concern them.

Or maybe it is impossible ?

Thank you

MR

 

 

What I have already done :

I tried to create an incident task (DLP Incident Manager > Incident task > Set Reviewer) : I selected my group TEST_GROUP in the list and then I put my system tree criteria. In Permission Sets > Data Loss Prevention > Incident Management > Incidents Access by Reviewer (advanced), I selected "Users can view incidents assigned to the following permission sets : TEST_GROUP.

If I select "User can view all incidents", my test user view all the incidents.

I hope it is clear.

1 Solution

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 4

Re: Permission sets for DLP

Jump to solution

Hello and thank you for posting here!

Based on the steps you've posted, that should work as you would expect. In fact, I tested your steps in my lab and was able to view only incidents that were generated by a system in a specific part of my system tree. When you ran the "DLP Set Reviewer for Operational Events and Incidents" server task, did the details of the task in the Server Task Log show that reviewers were applied to any incidents?

View solution in original post

3 Replies
Highlighted
Level 8
Report Inappropriate Content
Message 2 of 4

Re: Permission sets for DLP

Jump to solution
I forgot to put product versions :
ePO 5.10 Update 9
DLP 11.5
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 4

Re: Permission sets for DLP

Jump to solution

Hello and thank you for posting here!

Based on the steps you've posted, that should work as you would expect. In fact, I tested your steps in my lab and was able to view only incidents that were generated by a system in a specific part of my system tree. When you ran the "DLP Set Reviewer for Operational Events and Incidents" server task, did the details of the task in the Server Task Log show that reviewers were applied to any incidents?

View solution in original post

Highlighted
Level 8
Report Inappropriate Content
Message 4 of 4

Re: Permission sets for DLP

Jump to solution

Hello Corey,

Thank you for your quick reply!

In fact I didn't know I have to run a task to apply my choices, it's working fine now.

MR

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community