Storing evidence and fingerprints with Trellix DLP Endpoint - SaaS

Prev Next

Your evidence files, registered document fingerprints, and match highlights are stored using Amazon Simple Cloud Storage Service (Amazon S3). Trellix DLP Endpoint - SaaS needs to establish a connection with an existing S3 bucket. After a setup connection is established, a unique AWS bucket policy is generated which you copy to your S3 bucket policy.

Creating evidence storage in Amazon S3 and establishing a connection with your AWS bucket policy are requirements if you are enabling evidence in your Trellix DLP Endpoint - SaaS policy.

Evidence storage works as follows:

  1. The organization administrator configures the Amazon S3 bucket configurations in DLP Settings for uploading evidence files, match highlights, and fingerprints.

  2. Trellix DLP Endpoint - SaaS client generates incidents and policy configurations. This data is sent to ePO - SaaS.

  3. Evidence files are uploaded from Trellix DLP Endpoint - SaaS to the configured Amazon S3 bucket via the Trellix Cloud D2C (direct-to-cloud) component.

  4. You can retrieve the DLP incidents in ePO - SaaS.

Note

When you have reached your incidents quota limit, according to your license agreement, Trellix DLP Endpoint - SaaS purges incidents, starting with the oldest. Evidence files associated with these deleted incidents are kept for 90 days, and are then deleted after another 90 days from your AWS S3 bucket.

GUID-5FF2E6B9-D25C-4EB9-9AC3-897AF1EE94DB-low.png