Term | Definition |
|---|---|
Action | What a rule does when content matches the definition in the rule. Common examples of actions are block, encrypt, or quarantine. |
Crawling | Retrieving files and information from repositories, file systems, and email. Applicable to Trellix DLP Endpoint (Discovery) |
Classification | Used to identify and track sensitive content and files. Can include content classifications, content fingerprints, registered documents, and ignored text. |
Content classification | A mechanism for identifying sensitive content using data conditions such as text patterns and dictionaries, and file conditions such as document properties or file extensions. |
Content fingerprinting | A mechanism for classifying and tracking sensitive content. Content fingerprinting criteria specify applications or locations, and can include data and file conditions. The fingerprint signatures remain with sensitive content when it is copied or moved. |
Data vector | A definition of content status or usage. Trellix DLP protects sensitive data when it is stored (data at rest), as it is used (data in use), and when it is transferred (data in motion). |
Definition | A configuration component that makes up a classification. |
Discover server | The Windows Server where the Trellix DLP Discover software is installed. You can install multiple Discover servers in your network. |
DLP Server | A Trellix DLP Discover server that has the server role set to DLP Server. DLP Servers are used to store the registered document database. You can also configure DLP Server as a proxy server to copy evidence files to the evidence file share in scenarios where Trellix DLP Network doesn't have direct access to the evidence file share. |
Device class | A collection of devices that have similar characteristics and can be managed in a similar manner. Device classes apply to Windows computers only, and can have the status: Managed, Unmanaged, or Excluded. |
File information | A definition that can include the file name, owner, size, extension, and date created, changed, or accessed. Use file information definitions in filters to include or exclude files to scan. |
Fingerprinting | A text extraction procedure that uses an algorithm to map a document to signatures. Used to create registered documents and for content fingerprinting. |
FIPS compliancy | Cryptographic software is configured and used in a way that is compliant with Federal Information Processing Standard 140-2. |
Managed devices | A device class status indicating that Trellix Device Control manages the devices in that class. |
Match string | The found content that matches a rule. |
MTA | Message Transfer Agent or Mail Transfer Agent Software that transfers electronic mail messages from one computer to another using a client–server application architecture. |
Path | A UNC name, IP address, or web address. Trellix DLP Endpoint (Discovery) |
Policy | A set of definitions, classifications, and rules that define how the Trellix DLP software protects data. |
Redaction reviewer | Allows confidential information in the DLP Incident Manager and DLP Operations consoles to be redacted to prevent unauthorized viewing. |
RegDoc package | A package of fingerprint data produced by a Trellix DLP Discover registration scan. RegDoc packages are stored in a registration server (DLP Server) database and can be called by Trellix DLP Discover scans or Trellix DLP Network Monitor and Trellix DLP Network Prevent policies using REST API calls. |
Registered documents | Pre-scanned files from specified repositories. See Fingerprinting. Manual registration — Signatures of the files are uploaded to ePO - On-prem from Trellix DLP when you manually upload files and create a package. These signatures are made available to and downloaded by the endpoints and appliances from the shared location, which are used to track and classify content. |
Repository | A folder, server, or account containing shared files. The repository definition includes the paths and credentials for scanning the data. Trellix DLP Endpoint discovery. |
Rule | Defines the action taken when an attempt is made to transfer or transmit sensitive data. |
Rule set | A combination of rules. |
Scheduler | A definition that specifies scan details and the schedule type, such as daily, weekly, monthly, once, or immediately. Applicable to Trellix DLP Endpoint (Discovery) |
Strategy | Trellix DLP Endpoint divides applications into four categories called strategies that affect how the software works with different applications. In order of decreasing security, the strategies are Editor, Trusted, and Archiver. |
Unmanaged devices | A device class status indicating that the devices in that class are not managed by Trellix Device Control. Some endpoint computers use devices that have compatibility issues with the Trellix DLP Endpoint device drivers. To prevent operational problems, these devices are set to Unmanaged. |
Excluded devices | A device class status indicating that Trellix Device Control does not try to control the devices in that class. Examples are battery devices and processors. |
Glossary
- Published on Sep 1, 2026
- 3 minute(s) read
Trellix DLP terminology
Was this article helpful?