Help Center
Quick Start
- Overview
- System requirements
- Minimum privileges required
- Default port configuration
- Installing DataSecurity Plus
- Uninstalling DataSecurity Plus
- Starting DataSecurity Plus
- Launching DataSecurity Plus
- Configuring your solution
- Licensing details
- Applying a license
File Auditing
- About File Auditing
- Domain configuration
- File server configuration
- Failover cluster configuration
- NetApp server configuration
- Nutanix server configuration
- EMC Isilon server configuration
- Workgroup configuration
- Amazon FSx configuration
Setting up File Audit
Dashboard
Reports
Alerts
Configuration
Storage Configuration
File Analysis
- About File Analysis
- Domain configuration
- File server configuration
- Workgroup configuration
- SMB File Server Configuration
- On-Demand Reports
Setting up File Analysis
Dashboard
Reports
Alerts
Configuration
Data Risk Assessment
- About Data risk assessment
Setting up Data risk assessment
Dashboard
Reports
Ownership analysis
Configuration
Endpoint DLP
- About Endpoint DLP
- Domain configuration
- Workstation configuration
- Device group configuration
- Workgroup workstation configuration
Setting up Endpoint DLP
Reports
Alerts
Prevention policies
Configuration
Cloud Protection
- About Cloud Protection
- Gateway Server Installation Steps
- Gateway Configuration in Endpoint
- Gateway Cluster Configuration
- Gateway Server Management
- Certificate Authority Configuration
- Two-way SSL configuration
- Manage Certificate Trust Store
- Threat Analytics Database
- Manage Banned Applications
- Manage Authorized Applications
- Regenerating gateway server access key
- Updating gateway server
- Gateway Server Failover
- Load Balancer Configuration
- Global Insight
- Application Insight
- User Insight
- Shadow Application Insight
- Banned Application Insight
- Cloud App Discovery
- File Upload & Download Reports
- Control Policy reports
- General Reports
- Application Insights
- Shadow Domain Insights
- Banned Domain Insights
- GenAI Insights
Setting up Cloud Protection
Dashboard
Reports
Control Policies
Storage Configuration
Policy Management
Administrative settings
- Technician configuration
- Notification filters
- Manage agent
- Agent settings
- SIEM integration
- Business hours configuration
- Two-factor authentication
- Workgroup configuration
- Security policy
Email configuration
General settings
- Connection
- Personalize
- DataSecurity Plus Server
- Privacy Settings
- Disk utilization
- Schedule Retention Policy
Release notes
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
Troubleshooting
- HTTP communication failure
- Dormant DataEngine
- Secure Gateway server failure
- RPC communication failure
- Cloud Protection Gateway server failure
- Known issues and limitations
- Known errors and solutions
- Report discrepancy in File Analysis
Guides
- Agent document
- How to Migrate/Move DataSecurity Plus
- How to apply SSL certificate
- How to automate DataSecurity Plus database backup
- How to set alerts in DataSecurity Plus
- How to secure your DataSecurity Plus installation
Incident Management
Incident Management console
The Incident Management console is a centralized interface used to monitor, track, investigate, and resolve security incidents triggered by policy violations. It is designed to provide administrators with a single unified view of all incidents raised across DataSecurity Plus in real time.
When a policy is violated, an incident is automatically generated and logged in the console. This ensures that all security-relevant events are captured and acted upon promptly. At present, the console receives incidents exclusively from the DLP Policy Management module. Support for additional sources will be added in subsequent releases.
The incident response workflow:
- An event meets the conditions defined in a preconfigured DLP policy.
- The response specified in the policy—Block, Warn, or Allow—is executed.
- The event is automatically recorded as an incident in the Incident Management console.
- The administrator reviews the incident details and assigns it to an appropriate technician for investigation.
- The assigned technician analyzes audit logs, event context, and user activity to determine the cause and intent.
- Once the investigation is complete and necessary actions are taken, the incident is marked as resolved.
A sample scenario
An user attempts to send an Outlook email containing Social Security numbers to a recipient outside the pre-approved list. This action violates a preconfigured DLP policy. Now:
- DataSecurity Plus blocks this event and displays an in-product notification prompt saying, This action has been blocked as per the organization's data protection policy.
- DataSecurity Plus automatically creates an incident in the Incident Management console.
- The administrator reviews the incident to confirm that no sensitive data was exposed and assigns it to a technician for further investigation.
- The technician examines event details and evaluates the user's intent:
- If the action is legitimate, the technician should update the DLP policy by adding exclusions or refining its conditions.
- If the action is unauthorized or risky, the technician strengthens the policy or takes corrective action.
- Once addressed, the incident is marked as resolved.
How to view incidents
To check incident raised:
- Open the DataSecurity Plus web console. Choose Incident Management from the application drop-down at the top or from the Apps page.
- The Security Incidents page lists all incidents raised within ManageEngine DataSecurity Plus.
- Use the status filter at the top to view incidents by status—Open, In Progress, Dismissed, or Resolved—across different time periods.
Each incident entry includes the following details:
- User who triggered the event
- Device from which the event was triggered
- Communication channel across which the event was triggered
- Event time
- Severity of the incident
- Type of security threat
- Incident status
- Technician the incident is assigned to
How to review and manage incidents
- Open the DataSecurity Plus web console. Choose Incident Management from the application drop-down at the top or from the Apps page.
- On the Security Incidents page, hover over the desired incident and click View Details.
- On the Incident Details page, administrators and technician can review and update the following fields as needed:
- Incident name: Edit the name to reflect the nature of the incident.
- Description: Add or update a description to provide more context for the investigation.
- Status: Update the incident status to Open, In Progress, Dismissed, or Resolved as the investigation progresses.
- Severity: Adjust the severity level if required.
- Assignee: Assign the incident to the appropriate technician for investigation.
- Comment: Add comments to document findings, actions taken, or any other relevant notes.
For further investigation, use the tabs within the Security Incident page to scrutinize details such as:
Event Details
Reviews the specific event that triggered the incident, including basic information such as event time, triggered policy name, and the user who triggered it along with additional information about the exit point. For example, if the exit point is email, then this will include the email's body content, subject line, sender address, and number of attachments.
Data Identifiers Matched
Lists the specific data identifiers matched during the event along with the number of matches found for each identifier.
Timeline
Displays a chronological audit trail of all actions taken on the incident, including when it was created and by whom, and any subsequent updates made to it.
