Enable the DLP Capture feature and store captured items that can be searched later or used to tune rules and classifications..
Option definitions
Option
Definition
Apply Policy
By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.
Enable Capture
When selected, Trellix DLP Network can capture data for searching or tuning.
If an appliance contains captured content but the DLP Capture feature has been disabled on it, the captured content can still be searched.
Delete captured items older than (days)
When selected, enables the delete function. Select or enter the number of days in the field.
Default setting is 28 and you can enter a range between 1-1000 days.
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > The DLP Capture Search feature > Searching captured data > Working with the DLP Capture feature
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.14.x Product Guide > The DLP Capture Search feature > Searching captured data > Working with the DLP Capture feature
Data Loss Prevention (DLP) > Data Loss Prevention On-prem > Prevent > Trellix Data Loss Prevention Network Prevent 11.11.x Installation Guide - December 2025 > Trellix DLP implementation > Optional deployment scenarios