Trellix DLP Capture Settings

Prev Next

Enable the DLP Capture feature and store captured items that can be searched later or used to tune rules and classifications..

Option definitions

Option

Definition

Apply Policy

By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.

Enable Capture

When selected, Trellix DLP Network can capture data for searching or tuning.

If an appliance contains captured content but the DLP Capture feature has been disabled on it, the captured content can still be searched.

Delete captured items older than (days)

When selected, enables the delete function. Select or enter the number of days in the field.

Default setting is 28 and you can enter a range between 1-1000 days.