Get started with Trellix DLP

Prev Next

Use the DLP Getting Started feature to set up your license and shared location details, and to create your first Trellix DLP policy.

Make sure you have the minimum required permissions to create rules and policies in Trellix DLP. You must configure the following permissions for full use:

  • Policy Catalog for Trellix DLP Endpoint or Trellix DLP Discover, depending on your product

  • DLP Policy Manager

  • Classification

  • Definitions

To copy evidence using WebDAV, make sure that you enable WebDAV capability on the shared storage server.

Note

You must allow Incoming TCP HTTP port 80 on the WebDAV server to enable the Trellix DLP Endpoint to retrieve the regdocDB.dat file.

  1. In Trellix ePO - On-prem, select MenuData Protection DLP Getting Started.

  2. In the License page, enter the license key for each license you want to add, then click the checkmark.

    The licenses you enter activate the components available to you in the next steps of DLP Getting Started. It also activates the related components and Policy Catalogs.

  3. On the Shared location page, enter the UNC path (SMB) or the URL (WebDAV) to a shared location to save your evidence copy, registered documents, and ignored text. You have two options for shared location:

    • Enter your own credentials for a shared location. Click Test Credentials to make sure you entered the credentials correctly.

    • For Windows environment only, use the local Windows system account for your shared location.

    Note

    WebDAV (URL) is applicable only for Trellix DLP Endpoint for Windows. To enable HTTPS support for WebDAV, the relevant certificate authority (CA) certificates must be installed on the endpoints for successful SSL trust verification. For more details, see Import a CA certificate to Trellix ePO - On-prem

    License keys and shared location are mandatory steps for setting up your Trellix DLP environment and can be changed later in DLP Settings.

  4. On the Classifications page, select the classifications you want to protect from the Trellix DLP built-in classifications list.

    Note

    You can add user-defined classifications later from MenuData Protection Classification.

  5. On the Vectors page, click the checkbox next to each of the data vectors you want to protect. In the Email and Web fields, enter the domains you want excluded from this policy, for example, your organizational domains.

  6. On the Enforcement page, select the method of enforcement for this policy; Stealth, Coach, or Block.

  7. On the Exceptions page, select the User Groups and Users you want to exclude from your policy. If you haven't configured your Active Directory, click the Configure Active Directory link to add configuration details for your Active Directory servers.

  8. In the Policy Summary pane, review your selections and click Finish.

  9. (Optional) Click Start Over to return to the Classifications page and create another data protection rule.

    Note

    When you click Start Over, you can configure a new rule and rule set only. Go to DLP Policy Manager to assign this rule set to a policy.

Your Trellix DLP products are now registered and your first Trellix DLP policy is created. User notifications and blocked actions will be enforced based on your selected enforcement mode. Click one of the suggested links in the Next steps pane to continue setting up your Trellix DLP environment.