Evidence is stored in evidence folders on the network. You can specify a different storage share for each Trellix DLP product.
The number of evidence files stored per event has implications for storage volume, event parser performance, and the screen rendering (and thus user experience) of the DLP Incident Manager and DLP Operations pages.
Most rules allow the option of storing evidence. When this option is selected, an encrypted copy of the content is stored in the predefined evidence folder. Multiple evidence files are created for an event when possible. For example, if an Email Protection rule is triggered, the email, the body text, and the attachments are all saved as evidence files.
Note
If a classification occurs in the email headers, no separate evidence is written because it can be found in the message itself. The matched text is included in the hit highlights for the body evidence.
To handle different evidence requirements, Trellix DLP software does the following:
The UNC storage share and the maximum number of evidence files to store per event are set on the Shared Storage and Evidence page. Each instance of Windows client configuration, macOS client configuration, and server configuration can have different values for these parameters.
The DLP Incident Manager field Total Match Count displays the total evidence count.
If the evidence storage becomes critically full, Trellix DLP Network Prevent temporarily rejects the message with an SMTP error. An event is listed in the Client Events page, and an alert appears in the Appliance Management dashboard.
Purging evidence files
Evidence can contain information covered by policies or laws that regulate the storage of private information.
To optimize system performance, Trellix DLP purges incidents from the live incidents list table and moves them to the Incident History view when a million incidents are reached, starting with the oldest incidents.
The server task DLP Purge History of Operational Events and Incidents deletes events and incidents from the history database tables and marks evidence files for deletion. If the event or incident are still in the live incidents and operational events list tables, this task will delete them from the live tables. By default, this server task runs weekly. Evidence files are held for two calendar months, and if not required by another incident or operational event in the database, the files are deleted with the DLP purge evidences server task. By default, this server task runs weekly on Friday at 23:30.
Tip
Don't run DLP purge evidences when more than one ePO - On-prem instance shares an evidence storage path.