A VA scan runs one or more groups of tests on the database. Schedule a newly created VA scan at set intervals or choose to run an on-demand scan.
The available test groups are preconfigured, except for the custom test group that contains any customized tests defined in the VA Tests page. You can disable specific tests in a test group for a specific scan.
On the VA Scans page, in the VA Scan Configuration tab, click Create New Scan.
In the Scan Name field, enter a name for the scan. The name typed must clearly reflect the nature of the scan. For example, Monthly vulnerability scan of production databases.
In Scan by level, select the severity levels to be included in the scan.
(Optional) Select Rebuild password scan to recheck the database connections for the databases associated with the test group.
To determine which tests are to be performed as part of the scan:
In the Test Groups area, click Select Test Groups.
In the Test Groups dialog box, select one or more test groups.
Click Done to return to the scan properties page.
Note
You can filter the test group by name.
(Optional) To view the list of all tests or disable specific tests in the selected test groups:
Click Select Planned Tests.
In the Edit/View planned tests dialog box, click
to disable a specific test for this scan. The icon toggles to
.Note
You can filter the tests by Sysid or Name.
Click Done to return to the scan properties page.
In the Actions area, select the actions to be taken when a scan result is returned:
Trellix Database Security Console — Generates a result on the VA Results page based on the selected result priority.
Syslog — Sends the result to the Syslog.
Windows Event Log — Sends the result to the Windows event log.
Log to file — Sends the result to the log file.
Automatically resolve to — Resolves the result and assigns it as defined in the resolve type.
Send result to email — Sends an email notification in addition to the alert in the log, with the specified importance, low, medium, or high.
Note
To select the options, you need to enable these in System page.
To select the DBMSs for scanning:
In the Run on area, click DBMSs & Groups.
Install on DBMSs and DBMS Groups dialog box is displayed.
Select the DBMS groups and DBMS from the Install on DBMS Groups and Install on DBMSs tabs.
(Optional) To exclude any DBMS from scanning, select the required DBMS from the Exclude DBMSs.
Click Select to return to the scan properties page.
The selected DBMSs and DBMS groups are listed on the scan properties page.
To enable a scan, select Enable scan.
To schedule the scan to run at regular intervals, select the Schedule enabled checkbox, then configure the required scheduling intervals.
(Optional) In the Description field, enter a free text, description, or comment.
Click Save.
The new scan configuration is listed in the VA scan list.