Shared Storage and Evidence page

Prev Next

Use this page to configure the server Shared Storage and Evidence by selecting the Enforce on field.

Option definitions

Category

Option

Definition

Shared Storage

Storage Share Location

Specifies the SMB (UNC) path or the WebDAV URL to the evidence storage folder. To store evidence, specify a folder for evidence collection in this text box.

You can specify this path to store:

  • Evidence files

  • File with classification matches

  • Registered document fingerprints

    For Automatic Registered Document, Discover Server copies the fingerprint to the evidence share location defined in Server Configuration. DLP Server then loads the fingerprints from all evidence share of Discover Servers and makes it available through REST API.

    For Manual Registered Document, the fingerprints are copied to all available evidence share.

  • Package containing ignored texts

  • Exact database matches for Trellix DLP Network Prevent, Trellix DLP Network Monitor, and Trellix DLP Discover

  • Search results for Trellix DLP Network Prevent and Trellix DLP Network Monitor

Test Credential

Tests the connection to the storage share. You can save the configuration even if the test is unsuccessful.

Copy files using local system account

When selected, uses the system account to copy files. Trellix DLP Discover only.

Copy files using the following credentials

When selected, uses the specified user and password to copy evidence. Fill in the User Name, Password, and Confirm Password text boxes to specify a user.

For Trellix DLP Network Prevent, if you do not specify a user and password, the copy fails.

Evidence Storage HTTP Service

Enable Evidence Storage HTTP service

When selected:

  • Allows to act as a HTTP proxy for Trellix DLP Network Prevent and Trellix DLP Network Monitor when storing evidence files to the storage share.

  • stores the evidence files on behalf of Trellix DLP Network Prevent and Trellix DLP Network Monitor on the configured Storage Share (UNC).

Evidence Settings

Maximum evidence file size (MB)

The maximum size of an evidence file. Range: 10–2,575 Default: 25

Maximum local evidence age (Days)

The maximum number of days that evidence remains on the managed computer before it is deleted. Default: 30

Maximum evidence files to copy per event

Sets the maximum number of evidence files copied. Select options from 100–10000. Default: 100

Store original file

Toggle to enable/disable file storage. Default: Enabled

Classification matches file

Sets the hit highlighting display option. Default: Very low (20)

  • Disabled — Disables the hit highlighting feature

  • Very Low (20) (default)

  • Low (100)

  • Medium (200)

  • High (500)

  • Very High (1000)

  • Create all matches — 10000

The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted.

Incident Information

Report Short and Unique Match Strings in incident details

When selected, reports the short and unique match string in the incident details.

Note

The option to disable short match string reporting was added to comply with some recent legal and regulatory requirements.

Path

It shows the path of the main file and the relative path of sub-files.