File Retrieval

Prev Next

Use Trellix Agent and System Information Reporter (SIR) to collect specific files or directories from managed Windows endpoints. The SIR product generates a compressed zip file of the requested data on the client system, and Trellix Agent retrieves that zip file to the Trellix ePO - On-prem server for analysis.

Note

This feature is applicable only to Windows clients and Trellix ePO - On-prem environments. The presence of the System Information Reporter product is mandatory to use this feature.

Configure server storage for retrieved files

Define the storage path on the Trellix ePO - On-prem server before you run a retrieval task.

  1. Select MenuConfigurationServer Settings.

  2. Select Retrieve File Path from the Setting Categories list.

  3. In the Retrieve File path field, enter the directory where the server will store files uploaded from endpoints.

  4. Click Save.

Configure file size limits in the General policy

Specify maximum size of retrieved files to manage server storage and network bandwidth.

  1. Select MenuPolicyPolicy Catalog.

  2. Select Trellix Agent from the Product list and General from the Category list.

  3. Edit the policy.

  4. Click the Logging tab.

  5. In the Product Logs / File Retrieval section, specify the maximum size in the Zipped log file size limit (MB) field. The default size is 50 MB, and the maximum allowed size is 200 MB.

  6. Click Save.

  7. Assign and enforce the policy.

Create the System Information Reporter task

Use a client task to define the target files and generate a zip file on the managed system.

  1. Select MenuClient TasksClient Task Catalog click on System Information Reporter.

  2. Click New Task and click OK in the New Task Dialog.

  3. Enter a Task Name and a description.

  4. In the Retrieval path field, enter the file(s) or folder(s) to be retrieved.

    You can enter multiple paths on separate lines.

  5. (Optional) If you specified a folder, select Include subfolders.

  6. Click Save.

  7. Trigger the task on the endpoints via an Agent Wakeup call or wait for the next Agent-to-Server Communication Interval (ASCI).

  8. Once the task executes and the file is prepared, the System Information Reporter sends a Threat Event to the ePO server with the outcome of the task. The <host_name>.zip file is created on the client system at C:\ProgramData\SystemInformationReporter\FileRetrieval.

    Note

    This directory path is locked to restrict direct user access. Even if an error occurs while creating the requested data, a status file is still generated in this directory and can be retrieved by the Trellix Agent.

    For details, see SIR guide.

Retrieve the file from a managed system

After the SIR task generates the zip file, use the System Tree actions menu to retrieve it to the server.

  1. Select MenuSystemsSystem Tree.

  2. Select the target Windows system.

  3. Select ActionsAgentRetrieve File.

Verify retrieval status

Monitor the status of the file upload and locate the retrieved data.

  1. Select MenuAutomationServer Task Log.

  2. Locate the task named Retrieve File Task to verify if the upload completed successfully.

  3. Navigate to the local path you configured in the Server Settings to access the extracted files.