When enabled, the DLP Capture feature allows you to store email, web, and network data analyzed by Trellix DLP Network Prevent or Trellix DLP Network Monitor. The captured data can be searched later to identify a data loss event that was missed during real-time data analysis, or used to tune rules and classification settings to reduce false positives without affecting the analysis of live data.
You can create datasets that focus the search on specified properties to reduce the amount of data that will be searched on each system, so you get fewer and more targeted results.
You can create a Trellix DLP incident from a search result, then add the incident to a new or existing case. Any evidence associated with the search result can also be added to the incident.
Data and evidence storage
The captured data is stored on a disk on a physical or virtual system, or on an external storage device. The data is stored on a disk that is encrypted using a randomly generated encryption key. To recover the encrypted data, you can unlock it using the admin password. If you change the admin password, the unlock key is also updated. If you are upgrading from a previous version, the unlock key is a default value. You will see an alert in the Appliance Management dashboard until you change the password. To secure the encrypted data, change the admin password using the system console.
A captured event is stored on the system with its evidence. When a result is created, the associated evidence is copied to the evidence storage share.
Data retention
By default, captured data is removed automatically from storage after 28 days to avoid filling up the disk space but you can change that limit to a maximum of 1000 days if you want to.
Note
The Trellix DLP Network software regularly cleans the capture database, removing old data to make space for new data. The data is deleted from the capture database in any of the following scenarios:
The data age is older than the configured retention limit.
The storage space allocated for the data becomes full.
In either of these scenarios, the Trellix DLP Network software deletes the oldest data and frees up space for new data to be stored.
When the DLP Capture feature starts a search task, it collates the items that will be analyzed in the search. If some of those items are older items that must be removed while a search is in progress to free up storage space, the removed items are not analyzed but the search continues.
Users and permissions
The ability to tune rules or search captured data is not automatically available to all Trellix DLP users. Specify who can use the feature in the Data Loss Prevention permission set. Unlike previous versions of Trellix DLP that could capture content, this version allows several people to set up and run searches at the same time.