Use Trellix Agent and System Information Reporter (SIR) to collect specific files or directories from managed Windows endpoints. The SIR product generates a compressed zip file of the requested data on the client system, and Trellix Agent retrieves that zip file to the Trellix ePO - On-prem server for analysis.
Note
This feature is applicable only to Windows clients and Trellix ePO - On-prem environments. The presence of the System Information Reporter product is mandatory to use this feature.
Define the storage path on the Trellix ePO - On-prem server before you run a retrieval task.
Select → → .
Select Retrieve File Path from the Setting Categories list.
In the Retrieve File path field, enter the directory where the server will store files uploaded from endpoints.
Click .
Specify maximum size of retrieved files to manage server storage and network bandwidth.
Select → → .
Select Trellix Agent from the Product list and General from the Category list.
Edit the policy.
Click the Logging tab.
In the Product Logs / File Retrieval section, specify the maximum size in the Zipped log file size limit (MB) field. The default size is 50 MB, and the maximum allowed size is 200 MB.
Click .
Assign and enforce the policy.
Use a client task to define the target files and generate a zip file on the managed system.
Select → → click on System Information Reporter.
Click and click OK in the New Task Dialog.
Enter a Task Name and a description.
In the Retrieval path field, enter the file(s) or folder(s) to be retrieved.
You can enter multiple paths on separate lines.
(Optional) If you specified a folder, select Include subfolders.
Click .
Trigger the task on the endpoints via an Agent Wakeup call or wait for the next Agent-to-Server Communication Interval (ASCI).
Once the task executes and the file is prepared, the System Information Reporter sends a Threat Event to the ePO server with the outcome of the task. The
<host_name>.zipfile is created on the client system atC:\ProgramData\SystemInformationReporter\FileRetrieval.Note
This directory path is locked to restrict direct user access. Even if an error occurs while creating the requested data, a status file is still generated in this directory and can be retrieved by the Trellix Agent.
For details, see SIR guide.
After the SIR task generates the zip file, use the System Tree actions menu to retrieve it to the server.
Select → → .
Select the target Windows system.
Select → → .
Monitor the status of the file upload and locate the retrieved data.
Select → → .
Locate the task named Retrieve File Task to verify if the upload completed successfully.
Navigate to the local path you configured in the Server Settings to access the extracted files.