I am familiar with changing the evidence file path, but was wondering if there was a way to move old evidence to a new share. The evidence is currently in a location that we are trying to take offline perminantly. I haven't been able to locate a KB on this.
A new evidence share with a different UNC path such as evidence2$ can be created, and then edit the DLP Endpoint Agent Configuration to point to the new evidence2$ share. The clients upload new evidence files to the evidence2$ share. The DLP Endpoint incident manager can access the old evidence$ share, but all new evidence is placed in the new evidence2$ share.