I'm looking for ideas on how to effectively gather evidence from machines in remote locations, at remote sites, without bogging down their WAN connection. I was hoping there would be a way to have this data dumped to their local repositories, but that doesn't appear to be the case. Aside from limiting the amount of bandwidth each client can use to transmit, is there a way to intelligently route this traffic without saturating WAN links?
The answer is to specify different shares on other servers based on location in the system tree. For some reason I assumed the DLP Evidence share was a global setting and wasn't a flexible policy setting.