(This topic applies to Trellix DLP - SaaS.) Set up your default shared storage to store evidence files.
Before you begin
- Create an Amazon S3 bucket.
Note
After you create an Amazon S3 bucket, it can take up to 24 hours for the bucket name to propagate across all AWS Regions. During this time, you might receive the "307 Temporary Redirect" response for requests to regional endpoints that aren't in the same Region as the Amazon S3 bucket. For more information, see Temporary Request Redirection.
- Activate your Trellix DLP Discover – SaaS subscription in Trellix ePO - SaaS.
- Configure a proxy in your environment by using this command:
netsh winhttp set proxy <proxy:port>
Task
-
In
Trellix ePO - SaaS, select
Data Protection → DLP Settings.
DLP Settings opens on the General page.
-
Enter your Amazon S3 bucket name and click
Register Bucket.
A setup connection is established.
-
Click
Get Bucket Policy.
A copy of the policy shown in the JSON format.
-
Open your bucket policy in Amazon S3 and paste the policy from the previous step.
Note
For information about configuring the shared storage on Amazon S3 bucket, see KB92755.
- Click Test Connection to make sure Trellix ePO - SaaS can access your evidence storage.
- Set the shared password to use for uninstalling the software, removing files from quarantine, and encrypting evidence.
-
Set the policy validation mode to determine how policies are applied in your organization.
- Strict Mode — A policy with errors can't be applied.
- Non-Strict Mode — An administrator can force application of a policy with errors.
- No validation
- Click Save.
Results
Note
Evidence upload of large files to Amazon S3 storage can take a while to upload. Evidence files are available from incidents only after the upload to Amazon S3 bucket is completed.
What to do next
Verify that the S3 bucket is configured correctly, then apply and push the policy to the servers using the Wake Up Agents option. Before you push the server configuration policy changes for S3 bucket to the server, make sure that the policy is assigned to the server.
- In Trellix ePO - SaaS, go to Policy Catalog → Data Loss Prevention <version>, and click Server Configuration.
- Click the Edit link, to edit the policy, and select Evidence Copy Service.
- You can see the configured bucket name in S3 Bucket Name, if configured correctly. Click Apply Policy.
- To push the changes to the server immediately, go to System Tree → Systems, select the server, then click Wake Up Agents.
- In the Wake Up Trellix Agent page, select the Force complete policy and task update checkbox and continue to use the other default settings. Click OK.