Creating evidence folders

Prev Next

Evidence folders contain information used by all Trellix DLP software products for creating policies and for reporting. Depending on your Trellix DLP installation, certain folders and network shares must be created, and their properties and security settings must be configured appropriately.

Evidence folder paths are set in different locations in the Trellix DLP products. When more than one Trellix DLP product is installed in ePO - On-prem, the UNC paths for the evidence folders are synchronized.

Note

The evidence storage path must be a network share, that is, it must include the server name.

  • Evidence folder — Certain rules allow for storing evidence, so you must designate, in advance, a place to put it. For example, if a file is blocked, a copy of the file is placed in the evidence folder.

  • Copy and move folders — Used by Trellix DLP Discover to remediate files.

We suggest the following folder paths, folder names, and share names, but you can create others as appropriate for your environment.

  • c:\dlp_resources\

  • c:\dlp_resources\evidence

  • c:\dlp_resources\copy

  • c:\dlp_resources\move

Enable permissions to download evidence files when evidence share is on a different domain

When ePO - On-prem and evidence server are not on the same domain, you must configure the group policy settings on Windows to download evidence files from Incident Manager.

  1. On your evidence server, open the Local Group Policy Editor.

  2. Go to Computer ConfigurationWindows SettingsSecurity SettingsLocal PoliciesSecurity Options and configure these options:

    • Network access: Let Everyone permissions apply to anonymous users: Enabled

    • Network access: Shares that can be accessed anonymously: <evidence_share_folder>