How network discovery works

Prev Next

Trellix DLP Discover runs on Microsoft Windows servers and scans network file systems and databases to identify and protect sensitive files and data.

  1. ePO - On-prem applies policies and schedules scans.

  2. Trellix DLP Discover runs the scans, collecting results, applying classifications or rules, and reporting back to Trellix DLP.

  3. For registration scans, Trellix DLP Discover runs registration scans on repositories. Each scan is stored as a RegDoc package on the network evidence share. The DLP server loads all of the RegDoc packages. Trellix DLP Discover servers (and Trellix DLP Network Monitor and Trellix DLP Network Prevent servers) match fingerprints in the RegDoc packages to rules using REST API calls for classification and remediation scans.

GUID-C4047189-F827-45C6-93E9-D8446B774384-low.png

Trellix DLP Discover is a scalable, extensible software system that can meet the requirements of any size network. Deploy Trellix DLP Discover software to as many servers throughout the network as needed.

ePO - On-prem uses Trellix Agent to install and deploy the Trellix DLP Discover software to a Discover server — a designated Windows Server. For registration scans, where a registration database is also required, install DLP server software.

ePO - On-prem applies the scan policy to Discover servers, which scan the repository or database at the scheduled time. The data collected and the actions applied to files depend on the scan type and configuration. For database scans, the only actions available are to report the incident and store evidence.

Use ePO - On-prem to perform configuration and analytics tasks such as:

  • Displaying available Discover servers

  • Configuring and scheduling scans

  • Configuring policy items such as definitions, classifications, and rules

  • Reviewing data analytics and inventory results

  • Reviewing incidents generated from remediation scans

Supported repositories

File repositories:

  • Box

  • File Server — includes the following repository types:

    • Common Internet File System (CIFS)

    • Server Message Block (SMB)

    • Network File System (NFS) 2, 3

  • SharePoint 2010, 2013, 2016, and 2019

    Note

    SharePoint Enterprise Search Center (ESS) websites are not supported. An ESS website is a consolidation that does not contain files, but only links to the original files. For ESS websites, scan the actual site collections or the entire web application.

  • SharePoint Online

Databases:

  • Microsoft SQL

  • MySQL, commercial editions only

  • Oracle

  • Db2