Trellix DLP products identify sensitive data or user activity, take action on policy violations, and create incidents of violations.
Installing all Trellix DLP products allows you to use the full feature set of the product suite. The following diagram shows a simplified network where all Trellix DLP products and ePO - On-prem are deployed.
Administrators create policies in ePO - On-prem and deploy them to Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac clients.
Users create, save, and copy files or emails.
Trellix DLP Endpoint client applies policies and either blocks or allows user actions.
Applying the policies creates incidents that are sent to DLP Incident Manager for reporting and analysis.
Trellix DLP Discover scans files from local or cloud repositories and local databases, collecting file metadata.
Trellix DLP Discover receives classifications and policies from Trellix DLP to apply during classification or remediation scans.
DLP Server software creates registered documents databases for use in policies for Trellix DLP Discover, Trellix DLP Network Prevent, and Trellix DLP Network Monitor.
Incidents from remediation scans are sent to DLP Incident Manager for reporting and analysis.
Trellix DLP Network Prevent receives email from MTA servers and web traffic from web proxy servers. It analyzes the email messages and web traffic, applies the Trellix DLP policies, and sends incidents and evidence to DLP Incident Manager.
Trellix DLP Network Monitor analyzes network traffic, then creates incidents or saves evidence for the supported protocols. It applies network communication protection rules, web protection rules, or email protection rules.
