Using evidence and evidence storage

Prev Next

Evidence is a copy of the data that caused a security event to be posted to the DLP Incident Manager .

Trellix DLP Endpoint stores evidence in a temporary location on the client between agent-server communication intervals. When Trellix Agent passes information to the server, the folder is purged and the evidence is stored in the server evidence folder. You can specify the maximum size and age of local evidence storage when the computer is offline.

Prerequisites for evidence storage

Enabling evidence storage is the default condition for Trellix DLP. If you do not want to save evidence, you can disable the evidence service to improve performance. The following are either required or set as defaults when setting up the software:

  • Evidence storage folder — Creating a network evidence storage folder and specifying the UNC or WebDAV URL path to the folder are requirements for applying a policy to ePO - On-prem. Specify the default path on the DLP SettingsGeneral page.

  • Reporting Service — For Trellix DLP Endpoint for Windows, you must also activate the Reporting Service and Evidence Copy Service options in the Operational Modes and Modules page of the client configuration to enable evidence collection.