Add an evidence server to store incidents

Prev Next

Some incidents have evidence items associated with them. You can store the evidence on an evidence server.

The evidence server must be a CIFS or WebDAV share with read/write permissions.

Perform this task to configure the default shared evidence storage settings. The settings entered here are reflected in the policies configured in the Policy CatalogData Loss Prevention <version>Server Configuration, Policy CatalogData Loss Prevention <version>Windows Client Configuration, and Policy CatalogData Loss Prevention <version>Mac OS X Client Configuration pages. You can update the settings for the Trellix DLP Discover, Trellix DLP Network Prevent, Trellix DLP Network Monitor, and DLP Server in the Server Configuration policy.

  1. In ePO - On-prem, select MenuDLP SettingsGeneral.

  2. Enter the path to the evidence server in Shared Storage to save the settings and activate the software.

    The evidence storage path must be a network path or a URL, that is \\[server]\[share] or https:\\[server].

  3. Provide the user name and password to access the server, and click Save.