Datasets focus your rule tuning and forensic investigation searches on a subset of captured data to reduce the amount of data searched. When you search a data set, the time it takes to run the search is reduced, and the results are more useful and easier to analyze. There are some pre-defined datasets, or you can create your own based on properties such as email criteria, or user criteria.
If Trellix DLP Network can support the DLP Capture feature (that is, it has disks available for storing captured data and it contains some captured data), it can be added to a dataset and the captured data searched.
Note
If you create a dataset and do not specify a specific Trellix DLP Network system, any search that uses that dataset will evaluate all your Trellix DLP Network systems.
The user interface shows how many Trellix DLP Network systems will be searched as part of a dataset and an approximate number of captured events. The number of events is taken from the system in the dataset that contains the biggest number of captured events in the dataset.
For example, if the dataset contains four systems, and three of them contain 1,000 items and the fourth contains 3,000, the number you see will be 3,000. Trellix DLP Network systems are analyzed in parallel so you can use this number to help you decide whether the dataset needs further refining. When you save changes to the dataset, it shows you the revised number of captured events that will be searched with these properties.
Important
Changing definitions in a dataset used by either forensic investigation or rule tuning searches also changes that definition in any active rule sets that use it. Trellix recommends that you duplicate the definition and use the duplicate in your DLP Capture searches.
Datasets can be built using the following criteria:
Criteria | Definition |
|---|---|
DLP Capture-enabled appliances | The list of Trellix DLP Network systems that have the DLP Capture feature enabled. To search a specific DLP Capture-enabled system as part of a dataset, you need to select it in the dataset (or for the dataset to be "all" systems). To select a Trellix DLP Network system for a dataset, it needs to have sufficient storage available, and the DLP Capture feature needs to be enabled in the DLP Capture Settings policy. If Trellix DLP Network system has captured data but you subsequently disabled the DLP Capture feature in the policy, the system still appears in the list of datasets and the captured data will be included in the search. |
Incident Triggered | Adds events to the dataset that triggered an incident. |
Protocol | Select one or more protocols: FTP, HTTP, IMAP, IRC, LDAP, POP3, SMB, SMTP, Telnet. |
Subject | The subject line of an email message. |
Time Range | The period of time that the events were captured for, such as the last seven days. |
URL | The URL that the data was uploaded to if the original event was a web post. |
VLAN ID | (Trellix DLP Network Monitor only) Shows the VLAN that the traffic was sent on. |
Email Criteria | The email recipient and/or the email sender. |
IP Criteria | The destination IP and/or the source IP address. |
Port Criteria | The destination port and/or the source port. |
User Criteria | The destination user and/or the source user. |