Hit highlighting

Prev Next

The hit highlighting option helps administrators identify exactly which sensitive content caused an event.

When selected, it stores an encrypted XML evidence file with extracted text.

The evidence file is made up of snippets, also referred to as match strings, where a snippet for content classifications or content fingerprints typically contains the sensitive text, with 100 characters preceding it and 100 characters after it (for context) organized by the content classification or content fingerprint that triggered the event, and including a count of the number of events per content classification or content fingerprint. If there are multiple hits within 100 characters of the previous hit, those hits are highlighted, and the highlighted text together with the next 100 characters are added to the snippet. If the hit is in the header or footer of a document, the snippet contains the highlighted text without the 100 character prefix or suffix.

For Trellix DLP Endpoint, match count display option is set in the Shared Storage and Evidence page of the client configuration policy in the Classification matches file field. For Trellix DLP Endpointconfiguration options, see Trellix Data Loss Prevention Product Guide.

For Trellix DLP Network and Trellix DLP Discover, match count display option is set in Policy Catalog. From the MenuPolicyPolicy Catalog, navigate to Data Loss Prevention <version>Server Configuration. Create or edit the server configuration policy, and in Shared Storage and EvidenceEvidence Settings select the needed match count highlighting option from the Classification matches file field.

  • Disabled — Disables the hit highlighting feature

  • Very Low (20) (default)

  • Low (100)

  • Medium (200)

  • High (500)

  • Very High (1000)

  • Create all matches — highlights 10,000 matches

The match count file shows the Total Match Count and highlights the matches that are hit. The maximum number of hit highlights displayed depends on the option set in this field and shows the matches that are hit in a top-down order. If the total match count exceeds the configured value, the matches that are hit beyond the configured value aren't highlighted.

In the Incident Information field, you can choose to display the Short and Unique Match String on the incident details page. Short and unique match strings contain up to three hit highlights as a single string. Short and unique match strings, like other hit highlights, are saved as encrypted files.