- Go to Alert Center
- Choose Rule Policy – Incident tab
- The Incidents log is grouped by security policies and search criteria. Select the required security policy or search criterion. Documents that triggered incidents are displayed as a list in the results pane of the upper part of the window.

- The results pane contains the following elements:
- The Display drop-down list used to select incidents you want to display:
- All – displays all messages.
- Unread incidents – displays only unread incidents.
- Unread documents – displays only unread documents.
- Marked – displays only tagged incidents/documents.
When there are incidents/documents grouped by tags, the tag names will be also on the list, for example: Finance, Bank Statement, Personal data sheet.

- Incident View Mode

- Search for incidents/documents by ID
To find incident by its ID, select Actions > Find incident, or click Ctrl+F.

Enter the incident ID in the dialog box that appears.

Before searching by document ID, this document ID can be copied to the clipboard via the context menu command Copy document ID. This command can be also used if several documents are selected. In this case, comma is used to separate the IDs. Then document ID can be pasted in the text field via Ctrl+V combination.

- Search for criterion by name
To find a criterion, select Actions > Find criterion or click Ctrl+Alt+F.

Enter your query and press Enter.

Matching criteria are displayed.

- Context menu commands
Right-click on any of the documents in the list to open the context menu with the following commands:
- Open document
- Open with Analytic Console
- Report on incident
- Save document as
- Save as email
- Show document properties
- User card
- Add quick exception by attribute: the command is available only for the incidents detected by complex queries and search in database queries.
- Create a new task in Task Management: create a task related to this incident for investigation via Task Management.
- Add to task in Task Management: add the incident to Task Management task.
- Delete incident
- Delete all incidents created from this document
- Mark as read
- Mark as read (all pages)
- Mark as unread
- Tags (incidents, documents)
- Copy incident link to the clipboard – copy to the clipboard the command which you can execute in the file manager.
- Copy document ID
- Export list of incidents
- Integrations