When planning and configuring your scans, consider these items.
Directory exclusion
To avoid negative performance impacts, exclude Trellix DLP Discover directories and processes from these applications:
Antivirus software, including Trellix VirusScan Enterprise
Trellix Host Intrusion Prevention and other Trellix software
Firewalls
Access protection software
On-access scanning
Type | Exclude |
|---|---|
Processes |
|
Directories |
|
Registry keys |
|
Repository definitions
Configuring repository locations in ePO - On-prem has these limitations:
IP address ranges are supported for Class C addresses only.
IP address ranges can't include addresses ending in 0 or 255.
Note
You can define a single IP address ending in 0 or 255.
SharePoint scans
SharePoint scans don't crawl system catalogs, hidden lists, or lists flagged as NoCrawl. Because SharePoint lists are highly customizable, there might be other lists that are not scanned.
Most lists available out-of-the-box with the supported SharePoint versions can be crawled, such as:
Announcements
Contacts
Discussion boards
Events
Generic list
Issue trackers
Links
Meetings
Tasks
Individual items in a list are combined and grouped in an XML structure and are scanned as a single XML file. Files attached to list items are scanned as is.
Box scans
Configuring the same Box repository on multiple Trellix DLP Discover servers is not supported.
Scan ability varies depending on the account used. To scan other accounts, contact Box support to enable the as-user function.
The administrator account can scan all accounts.
A co-administrator account can scan its own account and user accounts.
A user account can scan only its own account.
Database scans
The following database column types are ignored during all Trellix DLP Discover scans. Text is not extracted, and classifications are not matched.
All binary types (blob, clob, image, and so forth)
TimeStamp ×
Note
In Microsoft SQL, TimeStamp is a row version counter, not a field with a time.
For Oracle databases, all multimedia types are ignored. This includes the following:
ADHEADER_TYP | ORDVIDEO | SI_STILLIMAGE |
ORDAUDIO | SI_COLOR | SI_TEXTURE |
ORDDOC | SI_COLORHISTOGRAM | TEXTDOC_TAB |
ORDIMAGE | SI_FEATURELIST | |
ORDIMAGESIGNATURE | SI_POSITIONALCOLOR |
Trellix DLP Discover database scans support special and foreign language characters in DB schemas, tables, and columns. But, if the scan encounters certain sequences of special characters in the names of databases, schemas, or tables, it might fail to read them. The unreadable sequences of special characters vary with database vendor. In this case, Trellix DLP Discover sends the vendor-defined error message and skips to the next object.
Database remediation scans now support reporting incidents per record. The Report Incident per Record field is only available when the scan type is set to Remediation. Inventory and Classification scans still report by table. The default is Do not report incidents. The drop-down list sets the number of incidents to report per DB table from 100–10,000.
If a database server is stopped (shut down) or disconnected during a scan, Trellix DLP Discover reports the run status as Stopped on the Scan Operations tab. The scan only restarts when the policy is reapplied.
Note
MySQL doesn't send a notification when the server stops running, so Trellix DLP Discover keeps running, trying to complete the scan.
Restarting Discover service in classification or remediation scans
Restarting the Discover service in the middle of a classification or remediation scan can skip some files. The persistency mechanism that restarts the scan remembers the container where the scan paused at the time that the service stopped. Scanning restarts from the beginning of that container. Sometimes a fetch task might still be running on files from the previous container when the service is stopped. When this occurs, the files are skipped. There is no way for the scan to recover these files.
Setting bandwidth for a scan
Large scans might take up noticeable bandwidth, especially on networks with low transmission capacities. By default, Trellix DLP Discover does not throttle bandwidth while scanning. If scan bandwidth is excessive, you can enable bandwidth throttling on the Scan Operations → Scan Details page .
When bandwidth throttling is enabled, Trellix DLP Discover applies it to individual files being fetched rather than as an average across the entire scan. Trellix DLP Discover fetches files in blocks. The scan software checks the speed after reading each block. If it is above the set speed, the software sleeps to lower the average speed. The throughput can be above or below the configured throttle limit while fetching a block, but files are now fetched in blocks of 16 kilobits to minimize spiking. A scan might burst above or below the configured throttle limit, but the average throughput measured across the entire scan remains very close to the configured limit. When enabled, the default throttling value is 2000 KBps.