The collect-attack-evidence enable command enables attack evidence collection of the antivirus (AV) function.
The undo collect-attack-evidence enable command disables attack evidence collection of the AV function.
The attack evidence collection function of AV is disabled by default.
The attack evidence collection function relies on hard disks and available only when the hard disks are installed.
You are advised to run the debugging collect-attack-evidence max-session-size max-session-size command to increase the threshold for the maximum data volume of attack evidence that the device can collect for a single session. The recommended threshold is 2000 KB.
Attack evidence collection is for troubleshooting only. Because attack evidence collection compromises system performance, you must enable it only when necessary and disable it immediately after you finish attack evidence collection.
After you enable attack evidence collection, the system collects virus-infected data packets when detecting a virus.
The auditor can choose on the Web UI to view and download virus-infected packets.