Set up a response rule to limit the retained data:
- Create a response rule.
- Set the action to "All: Limit Incident Data Retention".
- Enable "Discard Original Message" and select which data can be deleted (all, attachments w/ no violations, none).
Listed below are the default behaviors for the various DLP Servers:
- Endpoint and Endpoint Discover: does not retain original file by default
- Network Discover: There is no way to retain the original file
- All other Servers: Default behavior is to retain everything