Use the options in Trellix DLP Capture Settings to capture data from Trellix DLP Network and specify how long you want to retain that data for.
For the DLP Capture feature to appear in the ePO - On-prem menu, you must add a license for one of the Trellix DLP Network systems.
For details about product features, usage, and best practices, click ? or Help.
In ePO - On-prem, open the Policy Catalog.
Select the DLP Appliance Management product, select the Trellix DLP Capture Settings category, and open the policy that you want to edit.
In Capture Settings, select Enable Capture.
(Optional) Specify how long you want to keep captured items for.
By default, captured items are removed after 28 days. You can change the limit to a maximum of 1000 days.
Click Save.
(Optional) Check whether the DLP Capture feature is enabled on a specific appliance.
Open the System Tree and select the Systems panel.
Click the appliance to open the Systems: Information page.
Click Products and select DLP Capture.
Scroll down to General, and check the value for Capture Feature Status:
1: feature is enabled
2: feature is disabled
3: feature is not supported on this particular platform
3 is normally shown when the Trellix DLP Capture Storage Array needs to be attached and the appliance reimaged.