Your evidence files, registered document fingerprints, exact data fingerprints, and match highlights are stored using Amazon Simple Storage Service (Amazon S3). Trellix DLP Network Prevent – SaaS needs to establish a connection with an existing Amazon S3 bucket for saving or downloading these files.
Enabling evidence storage is the default condition for Trellix DLP Network Prevent – SaaS. Creating evidence storage in Amazon S3 and establishing a connection with your AWS bucket policy are the requirements, if you are enabling evidence storage in your ePO - SaaS policy.
Evidence storage works as follows:
The administrator configures the Amazon S3 bucket configurations in DLP Settings for uploading evidence files, match highlights, registered document fingerprints, and exact data fingerprints.
After a setup connection is established, a unique AWS bucket policy is generated, which you must copy to your Amazon S3 bucket policy.
Evidence files are uploaded from Trellix DLP Network Prevent – SaaS appliance to the configured Amazon S3 bucket.
You can retrieve the evidence files generated for DLP incidents from Protection Workspace of ePO - SaaS.
Note
When you have reached your incidents quota limit, according to your license agreement, ePO - SaaS purges incidents, starting with the oldest. Evidence files associated with these deleted incidents are kept for 90 days, and are then marked for deletion and deleted after another 90 days from your AWS S3 bucket.
.png)