Evidence is a copy of the file or email that triggers a security event. Create evidence storage folders and configure them with the required properties and security settings to make evidence available to the DLP Incident Manager. Both the ePO - On-prem server computer account and the domain user account need to have share permissions.
Enabling evidence storage is the default condition for Trellix DLP Endpoint. Creating an evidence storage folder and specifying the UNC path to the folder are requirements for applying a policy to ePO - On-prem. When more than one Trellix DLP product is installed in ePO - On-prem, the UNC paths for the evidence folders are synchronized.
We recommend creating the evidence share folder on a separate system than that of the ePO - On-prem and database server.
Create the evidence folder.
We suggest the following folder path, folder name, and share name but you can create others as appropriate for your environment.
<SharedLocation>:\resources\evidence
Note
The evidence storage path must be a network share. It must include the server name.
In Windows Explorer, right-click the evidence folder and select Properties.
Click the Sharing tab, then click Advanced sharing and select the Share this folder option.
Change the Share name to
evidence$. Click OK.The $ ensures that the share is hidden.
Click the Security tab to set the permissions for your evidence folder.
On the Permissions tab, click Edit and select your domain user account.
Select the Modify permissions checkbox. Click OK.
If you have several client configurations with different users that will upload evidence copy, repeat this step for every uploading user.
Click Edit again to select your ePO - On-prem server account.
To add your ePO - On-prem server account to the Group or user names list, click Add → Object Types and select Computers. Click OK.
Select the Modify permissions checkbox. Click OK.
Verify that permissions are applied correctly for the domain user and ePO - On-prem server accounts. On the Permissions tab, click Advanced and remove inherited permissions, if required.
Click OK and Close.