Configure settings for Trellix DLP Discover, Trellix DLP Network Prevent and Trellix DLP Network Monitor.
For Trellix DLP Discover server settings:
If you are using a Rights Management server, obtain the domain name, user name, and password.
If you plan to run remediation scans on SharePoint servers, determine if the SharePoint servers in your enterprise use the recycle bin. Mismatching this setting can lead to errors or unexpected behavior during the remediation scan.
If you plan to use the OCR feature, install the OCR package on top of Trellix DLP Discover server software. After updating Trellix DLP Discover server software, add the OCR license details and enable the OCR checkbox in the server configuration settings.
Additional OCR back-end configuration changes are needed for appliances. For information about the configuration, see KB95710.
Trellix DLP Network Prevent and Trellix DLP Network Monitor use the Shared Storage and Evidence and Optical Character Recognition (OCR) settings only.
Trellix DLP Discover can use all server setting options except ActiveSync Proxy, though some are optional.
In ePO - On-prem , select Menu → Policy → Policy Catalog.
On ePO - On-prem 5.10, select Data Loss Prevention <version>.
On ePO - On-prem 5.9 and earlier, from the Product drop-down list, select Data Loss Prevention <version>.
On ePO - On-prem 5.10, select Server Configuration.
(Optional) On ePO - On-prem 5.9 and earlier, from the Category drop-down list, select Server Configuration.
Do one of the following:
Click an existing policy to edit.
Click Duplicate on the Trellix Default configuration to create a copy of the default policy and update the policy.
(Optional, Trellix DLP Discover only) On the Box page, verify the options for trash and version history.
On the Shared Storage and Evidence page:
Enter the storage share and credentials. You can configure your evidence storage using Server Message Block (SMB) protocol or Web Distributed Authoring and Versioning (WebDAV).
SMB (UNC): Provide the share path in the UNC format. For example,
\\[server]\[sharename]\For Trellix DLP Network Prevent or Trellix DLP Network Monitor, specify a user name and a password. Do not select the Copy files using local system account option.
WebDAV (URL): Provide the shared location URL in http or https format. For example,
http(s)://[server]/[sharename]To enable HTTPS support for WebDAV, the relevant certificate authority (CA) certificates must be installed on the appliances for successful SSL trust verification.
Note
When a WebDAV server is set up using Microsoft Internet Information Services (IIS), the maximum allowed content length is 28 MB by default. This value needs to be increased to allow upload of files greater than 28 MB. For more information, see Change the file size limit on evidence uploads to WebDAV in the Trellix DLP Network Prevent or Trellix DLP Network Monitor Installation Guide.
If the policy must comply with privacy regulations such as GDPR, deselect the Incident Information → Report Short and Unique Match Strings in incident details checkbox.
Important
Selecting the Enable Evidence Storage HTTP service option takes priority over copying the evidence using the SMB (UNC) or WebDAV (URL) options.
If you are configuring an evidence server outside your firewall or if your appliance is in a demilitarized zone, select the Enable Evidence Storage HTTP service checkbox in the Shared Storage and Evidence page.
DLP Server can act as an HTTP proxy for Trellix DLP Network Prevent and Trellix DLP Network Monitor for saving evidence files and capture search evidences to storage share that they can't access directly. DLP Server, Trellix DLP Network Prevent and Trellix DLP Network Monitor must use the same settings for the evidence share location and credentials. If not, DLP Server does not store the files and returns an operation error. The Active Directory account lockouts can also occur when the same settings are not configured.
You can configure a DLP Server for evidence copy by creating or editing a policy from Policy Catalog → DLP Appliance Management → General. For more information, see Connect to an evidence server outside your firewall.
Note
If CIFS or WebDAV and DLP Server are configured for evidence copy, Trellix DLP Network Prevent and Trellix DLP Network Monitor always use only the DLP Server even if it fails and doesn't use the CIFS or WebDAV share.
(Optional, Trellix DLP Discover only) On the Debugging and Logging page:
Set the log output type and log level.
Tip
Use the default values.
Select on which Trellix DLP Discover process to run an Automatic Memory Dump for storing memory contents. Contents can be analyzed for system issues, such as a system crash.
Note
Analyzing the contents of a memory dump requires knowledge of developments tools, such as Microsoft Visual Studio.
On the Registered Documents page:
(Trellix DLP Discover only) Verify the Shared Storage (set on the DLP Settings → General page).
(Trellix DLP Discover and Trellix Network DLP) Verify that the Documents engine is enabled, and enter the IP address of the DLP Server .
The documents engine uses REST API to match fingerprints stored on the specified . If you are not using registered documents, you can disable the documents engine.
(DLP Server only) Enter the name, UNC storage share, and user name for the evidence shares to upload registered document packages to the DLP Server.
(Trellix DLP Discover only) On the Rights Management page, set the RM service credentials.
(Trellix DLP Discover only) On the SharePoint page, select, or deselect, Use Recycle bin when deleting a file.
Caution
If you enable this setting and the SharePoint server does not use the recycle bin, any Move actions taken on files fail and default to Copy. The default setting in SharePoint is to enable the recycle bin.
(Optional, Trellix DLP Discover only) On the Text Extractor page, configure the text extractor settings.
Tip
Use the default values.
Set the ANSI fallback code page.
The default uses the default language of the Discover server.
Set the input and output maximum file size, and the timeouts.
Select the Optical Character Recognition (OCR) checkbox if you want to extract text from image files.
Note
OCR is resource-intensive. It can significantly increase the scan time if you are scanning numerous images. Deselect the checkbox when you don't need OCR scanning.
Click Apply Policy.