Select ManageConfigurationData Loss PreventionSettingsSensitive Data.
In Evidence Storage, select Configure BucketAWS as the Public Storage Bucket.
In Instructions - AWS, locate the trust
relationship and access policy JSON provided to define the trust
relationship and access policy between the IAM role and Palo Alto
Networks.
The first JSON provided is the trust relationship and the second is
the access policy. Highlighted are the copy buttons that you will
use later on to create the IAM role for the S3 storage bucket.
Leave the Configure Bucket for Evidence
Storage display open and continue to create the
IAM role for the S3 storage bucket in a separate browser window.
Create the IAM role for the S3 storage bucket.
This role is required to allow the DLP cloud service to write to the S3
storage bucket.
Access to evidence storage settings and files on Strata Cloud Manager is allowed only for an account administrator or app
administrator role with Enterprise DLP read and
write privileges. This is to ensure that only the appropriate
users have access to report data and evidence.
Select ManageConfigurationSecurity ServicesData Loss PreventionSettingsSensitive Data and select AWS as the Public Cloud
Storage Bucket.
Select Input Bucket Details.
Enter the S3 Bucket Name of the bucket you
created.
The name you enter in the Strata Cloud Manager must match the name
of the S3 storage bucket on AWS.
Enter the Role ARN for the IAM role you
created.
The IAM Role ARN can be found in the IAM role
Permissions. The role ARN is displayed in
the Summary.
Select the AWS Region where the bucket is
located.
Select Connect to verify the connections status
your S3 storage bucket.
Select Save if Enterprise DLP can
successfully connect your bucket. A
Palo_Alto_Networks_DLP_Connection_Test.txt
file is uploaded to your storage bucket by the DLP cloud service to
verify connectivity.
If Enterprise DLP can't successfully connect your bucket,
select Previous and edit the bucket
connection settings.
Enable Sensitive Files for your enforcement
points.
You can enable evidence storage of sensitive files for Prisma Access, NGFW, and Endpoint DLP. Enable
evidence storage when prompted to confirm.