Azure Blob 存储:配置证据存储连接器

Prev Next

概况

To minimize data exposure and ensure compliance with regulatory requirements, you can create an integration with a third party for the storage of the evidence files.

This is supported for storing data from DLP policy violations. For more information, see Investigating DLP Violations with Forensic Evidence.

To configure the integration, you need to:

  1. Configure the integration storage application

  2. Create the API connector in the CMA

配置 Azure Blob 存储集成

要配置 Azure Blob 存储集成,请在您的 Azure 账户中创建所需的配置,然后在 CMA 中配置连接器。

步骤 1:在 Azure 中配置集成

要配置 Azure Blob 存储集成,请创建存储账户和容器。

要在 Azure 中配置集成:

  1. 在您的 Azure 门户中,导航到 存储账户。

  2. 若要将法证证据与现有存储账户集成,请点击该账户并转到步骤 4。 要创建新的存储账户,请点击 创建。

  3. 创建一个存储账户。 欲了解更多信息,请参阅 Microsoft 文档。

  4. 在存储账户的导航窗格中,导航到 数据存储 > 容器。

  5. 点击 + 容器。

  6. 创建容器。 欲了解更多信息,请参阅 Microsoft 文档。

  7. 复制并保存容器名称,以便输入到 CMA 中。

  8. 在存储账户中,导航到 安全 + 网络 > 访问密钥。 期间Always-On和防篡改被禁用多久。

  9. 复制并保存 连接字符串,以便输入到 CMA 中。

步骤2:在CMA中创建API连接器

在应用程序需要的集成设置之后,将详情添加到 CMA。

要在CMA中创建API连接器:

  1. 从导航菜单中,点击资源 > 集成。

  2. 点击 集成应用程序 标签。

  3. 新建集成 面板打开。

    新集成面板开启。

  4. 在SaaS 应用程序下拉菜单中选择Azure Blob Storage。

  5. 选择取证证据并在Auth下拉菜单中选择Api密钥。

  6. 添加这些配置:

    • 名称:为集成选择一个名称

    • Api密钥:连接字符串

    • 容器名称:在步骤1中创建的容器名称

    • 文件夹路径:选择一个文件夹路径,文件夹会自动创建

    • 权限:读/写

    • 选择是否通过创建事件来跟踪错误

  7. 点击 保存。

  8. 应用程序在集成应用程序表中可见,并显示为已连接状态。