Protecting files with discovery rules

Prev Next

Discovery rules define the content that Trellix DLP searches for when scanning repositories and determine the action taken when matching content is found. Discovery rules can be defined for Trellix DLP Discover or for Trellix DLP Endpoint discovery.

Depending on the type of rule, files matching a scan can be copied, moved, classified, encrypted, quarantined, content fingerprinted, or have a rights management policy applied. All discovery rule conditions include a classification.

Note

When using email storage discovery rules with the Quarantine prevent action, verify that the Outlook Add-in is enabled (Policy CatalogData Loss Prevention 10Client ConfigurationOperational Modes and Modules). You cannot release emails from quarantine when the Outlook Add-in is disabled.

Available discovery rules

Rule type

Product

Controls files discovered from...

Local File System

Trellix DLP Endpoint

Local file system scans.

Local Email (OST, PST)

Trellix DLP Endpoint

Email storage system scans.

File Server Protection

Trellix DLP Discover

File server scans.

SharePoint Protection

Trellix DLP Discover

SharePoint server scans.

Box Protection

Trellix DLP Discover

Box scans

Database Protection

Trellix DLP Discover

Database scans – Oracle, Microsoft SQL, MySQL, DB2



Note

Trellix DLP Discoverrules also require a repository. See the chapter Scanning data with Trellix DLP Discover for information on configuring rules and scans.

End-user initiated scans

When activated in the DLP Policy local file system scan configuration, end-users can run enabled scans and can view self-remediation actions. Every scan must have an assigned schedule, and the scan runs according to the schedule whether or not the user chooses to run a scan, but when the user interaction option is enabled, the end-users can also run scans at their convenience. If the self-remediation option is also selected, end-users and also perform remediation actions.

Local file system automatic classification

When the Classify File action is chosen for local file system discovery rules, the rule applies automatic classification, and embeds the classification Tag ID into the file format. The ID is added to all Microsoft Office and PDF files, and to audio, video, and image file formats. The classification ID can be detected by all Trellix DLP products and 3rd-party products.