Configure evidence file storage to securely store the evidence file for the DLP Incidents.

Before you begin

Role required: sn_dlir.admin

Verify that the Symantec user that you are configuring for ServiceNow Symantec DLP integration must have Body, Attachments and Original Message options enabled from Roles configuration page on Symantec DLP portal. For more information, see Display Attributes section available on Configuring Roles document for more information.

DLP Symantec - managing user roles.

About this task

You can configure the evidence file storage to securely store files. This provides an option for internal storage in ServiceNow instance, ensuring that files are stored and encrypted using ServiceNow's Column Level Encryption. For more information, see Field Encryption on NowPlatform documentation.

When DLP analyst performs the Download evidence files for DLP Incidents action from analyst workspace, the file will be downloaded from the selected storage if evidence file storage option is enabled. Otherwise, the file will be downloaded directly from the Symantec source and will not be persisted in ServiceNow instance.
Note: When a DLP analyst performs the Download evidence files for DLP Incidents action from analyst workspace, the file will be downloaded from the selected storage if evidence file storage option is enabled. Otherwise, the file will be downloaded directly from the Symantec source and will not be persisted in ServiceNow instance.

Procedure

  1. Navigate to All > Symantec DLP Integration > Incident Profile.
  2. Click on Evidence Storage section on the Incident Profile form.
  3. Select Evidence File Storage check box to enable the file storage.
  4. Select the preferred storage type.
    TypeDescription
    Evidence File Storage Option to enable the Evidence file storage.
    Storage Type Option to select the preferred storage type.
    Note: ServiceNow Storage: This will store the evidence files in the ServiceNow instance in an encrypted format.
  5. Click Continue and move to the Scheduling section.

Result

The evidence files are stored as per the configuration, after the incident ingestion is completed.