Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Creating Discovery Policies > Copying or moving discovered files > Preparing and running the remediation scripts
Preparing and running the remediation scripts
Administrator Help | Forcepoint DLP | Version 8.5.x
STEP 1: Configure CopyFiles and MoveFiles
1.
2.
Use the Location field to define the destination of the copied files. This location may be either a network share (UNC path) accessible to all servers and/or endpoints running discovery, or a local path on the server and/or endpoints running discovery. For example:
*
*
Using a network location is usually recommended but might not be possible if you are performing endpoint discovery on endpoints that are not always connected to the corporate network. When performing endpoint discovery and choosing a local quarantine, be sure to exclude that folder from all the discovery tasks to avoid triggering incidents on the quarantine.
Notice that the remediation script does not perform any deletions from the quarantine location, so it is up to you to perform routine cleanup operations on this location.
3.
4.
In the same directory, open the MoveFiles.py script in a text editor.
5.
Use the Location field to define the destination of the moved files. Refer to step 2 for requirements in this field.
*
*
6.
7.
In the Data Security module of the Forcepoint Security Manager, go to the Main > Policy Management > Resources   Remediation Scripts page.
8.
Select New > Endpoint Script or Policy Script.
9.
10.
Browse to the appropriate script: CopyFiles.py or MoveFiles.py.
It is not necessary to complete the fields on the Linux tab of the Add Policy Remediation Script window.
11.
a.
b.
c.
CopyFiles needs read permissions to all scanned files, and read/write permission to the archive (quarantine) folder. MoveFiles also needs write permissions to all scanned files.
12.
STEP 2: Add the remediation scripts to an action plan
1.
In the Data Security module of the Forcepoint Security Manager, go to the Main > Policy Management > Resources > Action Plans page.
2.
3.
*
Select Run remediation script, then select the script.
*
Select Run endpoint remediation script, then select the script to run for endpoint discovery.
4.
STEP 3: Add the action plan to a policy
1.
In the Data Security module of the Forcepoint Security Manager, go to the Main > Policy Management > Discovery Policies page.
2.
3.
Navigate to the Severity & Action page.
4.
5.
STEP 4: Deploy your changes
The remediation script will run when discovery incidents are triggered on the selected policy.
 
Note 

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Creating Discovery Policies > Copying or moving discovered files > Preparing and running the remediation scripts
Copyright 2017 Forcepoint. All rights reserved.