Reactions page

Prev Next

Use this page to define the actions and reporting for data protection, device protection, discovery, and application control rules.

Note

Data protection and device protection rules have a granular Action definition. You must define an action for each product selected in the Enforce on field. You can also define different actions for the following:

  • The computer is connected to the corporate network.

  • The computer is disconnected from the corporate network.

  • The computer is connected to the corporate network using VPN.

Discovery rules only apply when the computer is connected to the corporate network.

Option definitions

Option

Definition

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

For a list of prevent actions for different types of rules, see the respective Rules page and Reactions available for rule types.

User Notification

User notification definitions are stored in the DLP Policy Catalog. Select a predefined definition, or click New Item to create one.

Note

The user notification option does not appear when configuring discovery rules.

Report Incident

Select the checkbox for the rule to trigger a DLP Incident Manager report. For data protection and discovery rules, you can also store the original file.

Note

If multiple rules trigger, the incident is reported containing information about all triggering rules, even if only some of them have Report Incident selected.



These options apply to both the rule Definition and the rule Reaction.

Option definitions

Option

Definition

Rule name

Enter a unique name. This field is required.

State

Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting ActionsChange State. The default is Disabled.

Severity

A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field.

Enforce on

Determines the Trellix DLP product the rule is enforced on.

  • Data Protection rules — All other rules, except mobile protection rule can be enforced on Trellix DLP Endpoint for Windows. Some rules can also be enforced on Trellix DLP Endpoint for Mac or Trellix DLP Network Prevent.

  • Device Control rules — All rules can be enforced on Trellix DLP Endpoint for Windows. Plug and Play and Removable Storage device rules can also be enforced on Trellix DLP Endpoint for Mac

  • Discovery rules — Endpoint discovery rules are enforced on Trellix DLP Endpoint for Windows only. Network discovery rules are enforced on Trellix DLP Discover only.