When we enabled the default "Encrypted Files" in DSS, we observed that in the incidents, all data at the "Forensics" tab is nonsense, since it is encrypted. It would be great if there is a feature to disable collecting this forensics tab and hence the storing of this encrypted file per rule. With this, we can also save some space, which will be crucial for the uses longing more than 2 years.