Use this page to configure the client Shared Storage and Evidence for Trellix DLP Endpoint for Windows.
Category | Option | Definition |
|---|---|---|
Shared Storage | Shared Storage Location | The UNC path to the location on the server where evidence is saved. To collect evidence, specify a folder for evidence collection in this text box. You can specify these paths:
Specify this path to store:
|
Copy using the following credentials | When selected, uses the specified user and password to copy evidence. Fill in the User Name, Password, and Confirm Password text boxes to specify a user. | |
Use local Windows system account | You can use the local system account to copy evidence. Not supported by Trellix DLP Endpoint for Mac or Trellix DLP Network Prevent. | |
Test Credential | Tests the connection to the storage share. You can save the configuration even if the test is unsuccessful. | |
Client Settings | Maximum evidence file size (MB) | The maximum size of an evidence file. Range: 10–2,575 Default: 25 |
Free space on hard drive must be greater than (MB) | The minimum free space on the managed computer including the evidence storage space. Default: 250 | |
Maximum local evidence age (Days) | The maximum number of days that evidence remains on the managed computer before it is deleted. Default: 30 | |
Maximum evidence transmission bandwidth (KBps) | The network bandwidth available between the managed computer and the server. Default: 2048 | |
Maximum evidence files to copy per event | Sets the maximum number of evidence files copied. Select options from 100–10000. Default: 1000 | |
Store original file | Select from the drop-down list. Default: Enabled | |
Classification matches file | Sets the hit highlighting display option. Default: Very low (20)
The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted. | |
Incident Information | Report Short and Unique Match Strings in incident details | When selected, displays the short and unique match string on the Evidence tab of the incident details page. |