Before you begin, ensure you have a DFS namespace and folder configured with the necessary permissions for the evidence share account
Follow these steps to configure the DFS path in Trellix® ePolicy Orchestrator - On-prem.
In the main menu, go to the Data Protection → DLP Settings page.
Under the Shared Storage section, complete the following:
For Shared storage location, select SMB (UNC).
In the Path field, enter the full DFS network share path.
Provide the required credentials and click Test Credentials to verify the connection.
Click Save.
Apply the setting to the DLP policy.
From the Trellix ePO - On-prem menu, select Policy, then click Policy Catalog.
From the Product drop-down list, select Data Loss Prevention.
Select the policy you need to modify.
Click the Shared Storage and Evidence tab.
Configure the same DFS path that you entered in the DLP Settings.
Click Save.
Apply the updated policy to your client systems.
Verify the configuration
After you apply the policy, verify that evidence is being stored correctly.
On a client system where the policy is active, trigger a rule that generates an incident.
Verify the evidence file is accessible from the DLP Incident Manager.
From the Trellix ePO - On-prem menu, select Data Protection, then click DLP Incident Manager.
Locate the incident you generated.
From the Actions menu, download the evidence file.
Verify the evidence file exists on the DFS share by navigating to the DFS path and confirming that the correct evidence folder and file have been created.