Upon an incident violation in DLP, the encrypted files are copied to the "
repbuf" folder in the local disk. The files remain in the local disk until they're copied to the evidence share location. Once the copy process is complete, the local files are deleted. In case of any copy failure, the number of days for which to keep the evidence file in the "repbuf" folder and then retry the copy action can be configured in the Windows Client Configuration, Shared Storage and Evidence, Maximum local evidence age (Days). The file copies are retried until the configured number of days. If the age of the evidence file in the local disk crosses the configured value, the file is deleted without being copied. This leads to either missing or incomplete evidence files in the evidence share location.
NOTE: The cleaning activity is executed only when the DLP Endpoint works as normal with a successful connection to the ePolicy Orchestrator (ePO) and evidence share location.