Discovery rules define the content the crawler searches for, and what to do when this content is found.
Changes to a discovery rule take effect when the policy is deployed. If a scan is in progress when a rule is changed, the change takes effect the next time the scan runs.
For email storage (PST, mapped PST, and OST) scans, the crawler scans email items (body and attachments), calendar items, and tasks. It does not scan public folders or sticky notes.
In ePO - SaaS, select Menu → Data Protection → DLP Policy Manager.
On the Rule Sets page, select Actions → New Rule Set. Enter a name and click OK.
You can also add discovery rules to an existing rule set.
On the Discovery tab do one of the following:
Select Actions → New Endpoint Discovery Rule, then select either Local Email or Local File System.
select Actions → New Network Discovery Rule, then select File Server Protection.
The appropriate page appears.
(Optional) On the Exceptions tab, specify any exclusions from triggering the rule.
For Trellix DLP Endpoint - SaaS, enter a rule name and configure one or more classifications.
For ,Trellix DLP Discover – SaaS, enter a rule name and configure one or more classifications and repositories.
Enter a rule name and configure one or more classifications.
On the Reaction tab, select an Action from the drop-down list.
For Trellix DLP Discover – SaaS, the available reactions depend on the repository type.
(Optional) Select Report Incident options, set the State to Enabled, and select a Severity designation from the drop-down list.
Click Save.