Shared Storage and Evidence page for Mac OS X client

Prev Next

Use this page to configure the client Shared Storage and Evidence for Trellix DLP Endpoint for Mac.

Option definitions

Category

Option

Definition

Shared Storage

Storage Share Location

The UNC path for the location on the server where evidence is saved. To collect evidence, specify a folder for evidence collection in this text box. Specify this path to store:

  • Evidence files

  • File with classification matches

  • Endpoint discovery scan summary in CSV file format

Copy files using the following credentials

Uses the specified user and password to copy evidence. Fill in the User Name, Password, and Confirm Password text boxes to specify a user.

Test Credential

Tests the connection to the storage share. You can save the configuration even if the test is unsuccessful.

Client Settings

Maximum evidence file size (MB)

The maximum size of an evidence file. Range: 10–2,575 Default: 25

Free space on hard drive must be greater than (MB)

The minimum free space on the managed computer including the evidence storage space. Default: 250

Maximum local evidence age (Days)

The maximum number of days that evidence remains on the managed computer before it is deleted. Default: 30

Store original file

Select from the drop-down list. Default: Enabled

Classification matches file

Sets the hit highlighting display option. Default: Very low (20)

  • Disabled — Disables the hit highlighting feature

  • Very Low (20) (default)

  • Low (100)

  • Medium (200)

  • High (500)

  • Very High (1000)

  • Create all matches — 10000

The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted.

Incident Information

Report short match string in incident details

When selected, displays the short match string on the Evidence tab of the incident details page.