Overview
To minimize data exposure and ensure compliance with regulatory requirements, you can create an integration with a third party for the storage of the evidence files.
This is supported for storing data from DLP policy violations. For more information, see Investigating DLP Violations with Forensic Evidence.
To configure the integration, you need to:
- Configure the integration storage application
- Create the API connector in the CMA
Configuring the Azure Blob Storage Integration
To configure the Azure Blob Storage integration, create the required configurations in your Azure account, then configure the connector within the CMA.
Step 1: Configure the Integration in Azure
To configure the Azure Blob Storage integration, create a storage account and container.
To configure the integration in Azure:
In your Azure portal, navigate to Storage accounts.
To integrate forensic evidence with an existing Storage account, click on that account and go to step 4. To create a new Storage account, click Create.
Create a Storage account. For more information, see the Microsoft Documentation.
In the navigation pane for the storage account, navigate to Data storage > Containers.
Click + Container.
Create the Container. For more information, see the Microsoft Documentation.
Copy and save the Container name so it can be entered into the CMA.
In the Storage Account, navigate to Security + networking > Access keys.
Copy and save the Connection string so it can be entered into the CMA.
Step 2: Create the API Connector in the CMA
After you have set up an integration with the required application, add the details in the CMA.
To create the API connector in the CMA:
From the navigation menu, click Resources > Integrations.
Click the Integrated Apps tab.
Click New.
The New Integration panel opens.
In the SaaS Application dropdown, select Azure Blob Storage.
Choose Forensics Evidence and in the Auth drop-down, choose API key.
Add these configurations:
Name: Choose a name for the integration
API Key: The Connection string
Container Name: The name of the container you created in Step 1
Folder Path: Choose a folder path, the folder is automatically created
Permissions: Read/Write
Choose whether you want to track errors by creating an event
Click Save.
The app is visible on the Integrated Apps table with a Connected status.
0 comments
Please sign in to leave a comment.