Find an exact match in a data file

Prev Next

You can protect sensitive data using the Exact data matching (EDM) feature. Sensitive data or data records you want to protect must be saved in the form of .csv file and used as classifications to match data for any violation.

The feature in Trellix DLP Discover Trellix DLP Discover – SaaS supports exact data matching on File Server repositories.

Trellix DLP Network Prevent – SaaS appliances support scanning emails and web posts with EDM. Trellix DLP Network Monitor – SaaS appliances support scanning emails, web posts, and network traffic with EDM.

Data records are stored in CSV files as rows of data where the cells in each row are related, for example:

First name

Last name

Phone

Email

John

Doe

871-555-5555

j.doe@google.com

When you add an exact data match condition to a classification definition, apply that classification to the uploaded files and create an EDM package. Trellix DLP – SaaS makes the EDM package available for classification and remediation scans.

  1. Upload CSV files with the data records that you want to protect from being leaked.

    1. In ePO - SaaS, select MenuData ProtectionClassification.

    2. On the Register Documents tab, select Exact Data Fingerprints from the Type drop-down list.

    3. Click Upload file, select a CSV or .zip file to upload, then click OK.

    4. For uploads with more than 100,000 records, click the executable link to open the CSV2Fingerprints.exe utility.

  2. Create or add an exact data match condition.

    1. In ePO - SaaS, select MenuData ProtectionClassification.

    2. Optional: Create a classification — select ActionsNew Classification in the classifications list.

      You can also add an EDM condition to an existing classification.

    3. Select ActionsNew Content Classification Criteria.

    4. From the Data conditions list, select Exact Data Matching.

    5. Click the choose icon (GUID-48F0BA2A-5E0A-4652-AB28-768626FD7198-low.gif) next to the Value field.

      The Exact Data Fingerprints Match Criteria page appears.

      GUID-75A4F6BB-72C2-42C5-8525-0C8B1F1B0624-low.png
    6. Click the choose icon and select a CSV file from the list of files you uploaded. Fill in the match criteria and number of records to match. Click OK.

  3. Create the package. On the Register Documents tab, select Exact Data Fingerprints from the Type drop-down list, then click Create package.

    All uploaded documents are added to the package, and the package is copied to the network evidence share folder.

  4. (For Trellix DLP Discover only) Create a network discovery rule.

    1. In the DLP Policy Manager, open a rule set or create one.

    2. On the Discovery tab, select ActionsNew Network Discovery Rule, then select one of the repository types supported by the feature (File Server) .

    3. Select the classification you created in Step 2 and a repository that matches the type selected in Substep b. Fill in the rest of the fields, and click Save.

  5. (For Trellix DLP Discover – SaaS only) Run the scan.

    1. Go to Data ProtectionDLP Discover to open the Scan Management page.

    2. Click New scan and enter the required details for the scan.

      Select the rule set that includes the rule created in step 4.

    3. Click Save and Apply Policy.