Configure cloud storage for evidence and fingerprint files

Prev Next

(This topic applies to Trellix DLP - SaaS.) Set up your default shared storage to store evidence files.

Before you begin

  • Create an Amazon S3 bucket.

    Note

    After you create an Amazon S3 bucket, it can take up to 24 hours for the bucket name to propagate across all AWS Regions. During this time, you might receive the "307 Temporary Redirect" response for requests to regional endpoints that aren't in the same Region as the Amazon S3 bucket. For more information, see Temporary Request Redirection.

  • Activate your Trellix DLP Discover – SaaS subscription in Trellix ePO - SaaS.
  • Configure a proxy in your environment by using this command:

    netsh winhttp set proxy <proxy:port>

Task

  1. In Trellix ePO - SaaS, select Data ProtectionDLP Settings.
    DLP Settings opens on the General page.
  2. Enter your Amazon S3 bucket name and click Register Bucket.
    A setup connection is established.
  3. Click Get Bucket Policy.
    A copy of the policy shown in the JSON format.
  4. Open your bucket policy in Amazon S3 and paste the policy from the previous step.

    Note

    For information about configuring the shared storage on Amazon S3 bucket, see KB92755.

  5. Click Test Connection to make sure Trellix ePO - SaaS can access your evidence storage.
  6. Set the shared password to use for uninstalling the software, removing files from quarantine, and encrypting evidence.
  7. Set the policy validation mode to determine how policies are applied in your organization.
    • Strict Mode — A policy with errors can't be applied.
    • Non-Strict Mode — An administrator can force application of a policy with errors.
    • No validation
  8. Click Save.

Results

Your shared storage is now configured. The Amazon S3 bucket configurations are automatically copied to your server configuration policies assigned to your appliances.

Note

Evidence upload of large files to Amazon S3 storage can take a while to upload. Evidence files are available from incidents only after the upload to Amazon S3 bucket is completed.

What to do next

Verify that the S3 bucket is configured correctly, then apply and push the policy to the servers using the Wake Up Agents option. Before you push the server configuration policy changes for S3 bucket to the server, make sure that the policy is assigned to the server.

  1. In Trellix ePO - SaaS, go to Policy CatalogData Loss Prevention <version>, and click Server Configuration.
  2. Click the Edit link, to edit the policy, and select Evidence Copy Service.
  3. You can see the configured bucket name in S3 Bucket Name, if configured correctly. Click Apply Policy.
  4. To push the changes to the server immediately, go to System TreeSystems, select the server, then click Wake Up Agents.
  5. In the Wake Up Trellix Agent page, select the Force complete policy and task update checkbox and continue to use the other default settings. Click OK.