Shared Storage and Evidence page

Prev Next

Use this page to configure the client Shared Storage and Evidence for Trellix DLP Endpoint for Windows.

Option definitions

Category

Option

Definition

Shared Storage

Shared Storage Location

The UNC path to the location on the server where evidence is saved. To collect evidence, specify a folder for evidence collection in this text box. You can specify these paths:

  • SMB (UNC)

  • WebDAV (URL)

Specify this path to store:

  • Evidence files

  • File with classification matches

  • Registered document fingerprints.

    For Manual Registered Document, the fingerprints are copied to all available evidence share.

  • Package containing ignored texts

  • Endpoint discovery scan summary in CSV file format

Copy using the following credentials

When selected, uses the specified user and password to copy evidence. Fill in the User Name, Password, and Confirm Password text boxes to specify a user.

Use local Windows system account

You can use the local system account to copy evidence. Not supported by Trellix DLP Endpoint for Mac or Trellix DLP Network Prevent.

Test Credential

Tests the connection to the storage share. You can save the configuration even if the test is unsuccessful.

Client Settings

Maximum evidence file size (MB)

The maximum size of an evidence file. Range: 10–2,575 Default: 25

Free space on hard drive must be greater than (MB)

The minimum free space on the managed computer including the evidence storage space. Default: 250

Maximum local evidence age (Days)

The maximum number of days that evidence remains on the managed computer before it is deleted. Default: 30

Maximum evidence transmission bandwidth (KBps)

The network bandwidth available between the managed computer and the server. Default: 2048

Maximum evidence files to copy per event

Sets the maximum number of evidence files copied. Select options from 100–10000. Default: 1000

Store original file

Select from the drop-down list. Default: Enabled

Classification matches file

Sets the hit highlighting display option. Default: Very low (20)

  • Disabled — Disables the hit highlighting feature

  • Very Low (20) (default)

  • Low (100)

  • Medium (200)

  • High (500)

  • Very High (1000)

  • Create all matches — 10000

The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted.

Incident Information

Report Short and Unique Match Strings in incident details

When selected, displays the short and unique match string on the Evidence tab of the incident details page.