Create a Data Loss Prevention Incident Response SLA trigger

  • Release version: Zurich
  • Updated July 31, 2025
  • 1 minute to read
  • Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.

    Before you begin

    Role required:
    • sn_dlir.admin - Create, update, and delete DLP SLA triggers
    • sn_dlir.analyst.read - Read Trigger table.

    Procedure

    1. Navigate to All > DLP Administration > SLA Triggers.
    2. Select New to create the SLA trigger.
      Field Description
      Name Name of the trigger
      Order Order in which the trigger is considered.
      Active Option to evaluate the SLA trigger.
      Trigger when a DLP incident is updated Option to evaluate the trigger condition on each update of the DLP incident.
    3. Configure a condition by selecting the rule record and defining conditions in the Trigger Condition field.
      For example, the trigger condition to set SLAs on DLP incidents from an email scan source would be [Scan Source][is][Email SMTP].
    4. Select Submit.

    Result

    Once a task SLA record for a Data Loss Prevention Incident Response incident is created, the SLA records tab becomes visible for that particular incident in the workspace. This tab enables you to use an SLA system for your organization's task.