Advanced patterns are used to define classifications. An advanced pattern definition can consist of a single expression or a combination of expressions and false positive definitions.
Advanced patterns are defined using regular expressions (regex).
Note
There is no equivalent to the Percentage match and Number of bytes from the beginning options in Trellix DLP – SaaS Appliances.
In ePO - SaaS, select Menu → Data Protection → Classification.
Select the Definitions tab, then select Advanced pattern in the left pane.
To view only the user-defined advanced patterns, deselect Include Built-in items. User-defined patterns are the only patterns that can be edited.
The available patterns appear in the right pane.
Select Actions → New.
Enter a name and optional description.
Under Matched Expressions:
Enter an expression in the text box and add an optional description.
Select a validator from the drop-down list or if validation is not appropriate for the expression, select No Validation.
Enter a number in the Score field to indicate the weight of the expression in threshold matching.
Click Add.
Under Ignored Expressions:
Enter an expression in the text box.
If you have text patterns stored in an external document, copy them into the definition with Import Entries.
In the Type field, select RegEx from the drop-down list if the string is a regular expression, or Keyword if it is text.
Keyword expressions can also be added using Import Keywords, entering keywords separated by a new line.
Click Add.
Add the count to the concept:
Give all expressions a score of 1.
Select count multiple occurrence of each match string if the score must be added for multiple occurrence of a single expression in a document.
Select count each match string only one time if the score must not be added and must be one even when multiple occurrences of a single expression are present in a document.
Select start with and end with to see if the document starts or ends with the expression, or select both options to find the expression anywhere in the document.
To match on the number of lines from the beginning of the document, you can create a new regular expression using conditions such as less than, equals, or greater than.
Click Save.