Configure a remediation scan to classify and enforce rules on files in your repository

Prev Next

Remediation scans apply rules to protect sensitive content in the scanned repository. You can create a remediation scan to detect if any data in your repository violates a policy. You can apply rules to move, copy, or monitor files using the remediation scan.

  • Configure a Trellix DLP Discover server.

  • Configure evidence storage on Amazon S3.

  • Create the classifications and rules for the scan.

  • Configure server settings, if needed.

  • Create schedules in DLP Policy ManagerDefinitionsScheduler.

  • Make sure you have these permissions in Users & Roles:

    • DLP Discover

    • DLP Policy Manager

    For a non-administrator user, you can assign these permissions from MenuConfigurationUsers & RolesSelect specific user or roleData Loss PreventionDLP Discover or DLP Policy Manager.

  • A non-administrator user needs the Data Loss Prevention: View and edit policies permission with other permissions such as DLP Discover and DLP Policy Manager to create a scan. To assign this permission, go to MenuConfigurationUsers & RolesSelect specific user or roleMVISION ePolicy OrchestratorPolicyData Loss Prevention: View and edit policies.

  1. Log on to ePO - SaaS.

  2. Go to Data ProtectionDLP Discover.

  3. On the Scan Management page, click New Scan.

  4. Enter details in General Settings:

    1. On the right pane, enter a name for your scan.

    2. Select scan type as Remediation.

      The fields applicable for remediation scan appear in the pane.

    3. Enable the scan by moving the slider to blue. By default, the scan is disabled.

    4. To select a Discover server for the scan, click Add from catalog to open the Discover Servers pane, then click + to add the server to the scan.

      At least one Discover server must be selected.

      You can click the Discover Server name and view the details. In the Discover Server details section, Last Communication shows the last time when a Discover server error occurred.

    5. To set a specific schedule to run the scan, select from the Schedule drop-down list.

      You can use the default schedule and set the scan to run immediately, weekly, or monthly. You can edit or create schedules in DLP Policy ManagerDefinitionsScheduler.

  5. In the Repositories section, click Add from catalog to open the Repositories pane, then click + to add more repositories that need to be scanned.

  6. In the Rule Sets section, click Add from catalog to open the Rule Sets pane, then click + to add more rules that you want to include in your scan.

    You can create rule sets in DLP Policy ManagerRule Sets.

  7. Use filters to include or exclude file information definitions to make the scan more granular.

    • Include files — To include only specific file types, select Specific Files from the drop-down list, then in the File Information pane, click + to add the file types that you want to include in the scan. The default value is All Files.

    • Exclude files — To exclude specific files from the scan, select Specific Files from the drop-down list. Then, in the File Information pane, click + to add the file types that you want to exclude from the scan. The default value is Nothing.

  8. Set more options for the scan.

    • To limit excessive scan bandwidth for large scans that are scheduled on networks with low transmission capacities, select Throttling limit in KBps.

    • To set the maximum number of incidents to be reported per scan run, select a value from the Maximum incidents to report per run drop-down list. The default value is 100. You can stop the scan when the number of incidents exceed a specific value. To do this, select Stop scan if number exceeds and select a value from the drop-down list.

    • To set the maximum number of errors to report per scan run, select a value from Maximum errors to report per run. The default value is 100. You can stop the scan when the number of errors exceed a specific value. To do this, select Stop scan if number exceeds and select a value from the drop-down list.

  9. Click Save and Apply Policy.

The remediation scan is created and appears on the Scan Management page. After you click Apply policy, the scan starts only when the next agent-server communication happens. The default and minimum agent-server communication interval is 60 minutes.

To change the agent-server communication interval, go to Policy CatalogTrellix AgentGeneral. Create a duplicate or edit an existing policy. In the General tab, change the value of Agent-to-server communication interval (minutes) as needed.

To start the scan immediately, if you have selected the Run Immediately schedule:

  1. Go to MenuSystemsSystem Tree.

  2. Select the checkbox of one or more Trellix DLP Discover servers selected for the scan.

  3. Click Wake Up Agents to run the scan immediately.

    The Wake Up Trellix Agent window opens.

  4. Next to Wake-up call type, select Agent Wake-Up Call.

  5. Accept the default Randomization (0–60 minutes) or type a different value.

    If you type 0, agents respond immediately.

  6. Click OK to send the wake-up call to the Discover servers.