The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Move or remove incidents from a case

Prev Next

If an incident is no longer relevant to a case, you can remove it from the case or move it to another case.

For details about product features, usage, and best practices, click ? or Help.

  1. In ePO - On-prem, select Menu → Data Protection → DLP Case Management.

  2. Click a case ID.

  3. Perform any of these tasks.

    • To move incidents from one case to another:

      1. Click the Incidents tab and select the incidents.

      2. Select Actions → Move, then select whether to move to an existing or new case.

      3. Select the existing case or configure options for a new case, then click OK.

    • To remove incidents from the case:

      1. Click the Incidents tab and select the incidents.

      2. Select Actions → Remove, then click Yes.

  4. Click OK.

Tip

You can also move or remove one incident from the Incidents tab by clicking Move or Remove in the Actions column.