Repositories and credentials for scans

Prev Next

Trellix DLP Discover – SaaS supports File Server repositories.

File Server repositories

File Server repositories can be either SMB/CIFS or NFS. When defining a File Server repository, the UNC path can be the fully qualified domain name (FQDN) (\\myserver1.mydomain.com) or the local computer name (\\myserver1). You can add both conventions to a single definition.

In the Linux environment, NFS path descriptions are case sensitive. You are allowed, for example, to have path \\server\share\folder and path \\server\share\FOLDER. DLP File Server repository definitions validate the paths you enter to prevent path repetition, so the example given is not valid for a single File Server repository definition. If you want to scan both paths, one solution is to enter the parent path (\\server\share) and scan all subfolders. Another solution is to define each path in a separate definition and add both repository definitions to the discovery rule.

File Server repositories support read-only permissions. If you scan a File Server repository when the user has read-only permissions, the last access time is changed. To preserve the file's last access time, select the option to skip files for which the user doesn't have write permissions. This can be done when you create the File Server repository definition. By default, classification and remediation scans fail to read the file if the user has only read-only permissions. To support classification and remediation scans with read-only permissions, change the default setting in the Scan Management page for an existing or new scan to Always inspect file content. You can access the Always inspect file content via RepositoriesCredentials on the Scan Management page.

A credential definition is specific to a File Server repository definition. In the credentials definition, if the user is a domain user, use the FQDN for the Domain name field. If the user is a workgroup user, use the local computer name. If the repository definition contains only one UNC version, for example FQDN, you must use that version in the credential definition.

Using incorrect credentials creates an event indicating the reason for the scan failure. View the event in the Operational Event Management page for details.