Scan considerations and limitations

Prev Next

When planning and configuring your scans, consider these items.

Directory exclusion

To avoid negative performance impacts, exclude Trellix DLP Discover directories and processes from these applications:

  • Antivirus software, including Trellix VirusScan Enterprise

  • Trellix Host Intrusion Prevention and other Trellix software

  • Firewalls

  • Access protection software

  • On-access scanning

Trellix DLP Discover Items to exclude

Type

Exclude

Processes

  • dscrawler.exe

  • dseng.exe

  • dssvc.exe

  • dstex.exe

Directories

  • c:\programdata\mcafee\discoverserver

  • c:\program files\mcafee\discoverserver

Registry keys

  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\DiscoverServer

  • HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DiscoverServer

  • HKEY_LOCAL_MACHINE\SOFTWARE\ODBC.INI\McAfeeDSPostgres



Repository definitions

Configuring repository locations in ePO - On-prem has these limitations:

  • IP address ranges are supported for Class C addresses only.

  • IP address ranges can't include addresses ending in 0 or 255.

    Note

    You can define a single IP address ending in 0 or 255.

SharePoint scans

SharePoint scans don't crawl system catalogs, hidden lists, or lists flagged as NoCrawl. Because SharePoint lists are highly customizable, there might be other lists that are not scanned.

Most lists available out-of-the-box with the supported SharePoint versions can be crawled, such as:

  • Announcements

  • Contacts

  • Discussion boards

  • Events

  • Generic list

  • Issue trackers

  • Links

  • Meetings

  • Tasks

Individual items in a list are combined and grouped in an XML structure and are scanned as a single XML file. Files attached to list items are scanned as is.

Box scans

Configuring the same Box repository on multiple Trellix DLP Discover servers is not supported.

Scan ability varies depending on the account used. To scan other accounts, contact Box support to enable the as-user function.

  • The administrator account can scan all accounts.

  • A co-administrator account can scan its own account and user accounts.

  • A user account can scan only its own account.

Database scans

The following database column types are ignored during all Trellix DLP Discover scans. Text is not extracted, and classifications are not matched.

  • All binary types (blob, clob, image, and so forth)

  • TimeStamp ×

    Note

    In Microsoft SQL, TimeStamp is a row version counter, not a field with a time.

For Oracle databases, all multimedia types are ignored. This includes the following:

ADHEADER_TYP

ORDVIDEO

SI_STILLIMAGE

ORDAUDIO

SI_COLOR

SI_TEXTURE

ORDDOC

SI_COLORHISTOGRAM

TEXTDOC_TAB

ORDIMAGE

SI_FEATURELIST

ORDIMAGESIGNATURE

SI_POSITIONALCOLOR

Trellix DLP Discover database scans support special and foreign language characters in DB schemas, tables, and columns. But, if the scan encounters certain sequences of special characters in the names of databases, schemas, or tables, it might fail to read them. The unreadable sequences of special characters vary with database vendor. In this case, Trellix DLP Discover sends the vendor-defined error message and skips to the next object.

Database remediation scans now support reporting incidents per record. The Report Incident per Record field is only available when the scan type is set to Remediation. Inventory and Classification scans still report by table. The default is Do not report incidents. The drop-down list sets the number of incidents to report per DB table from 100–10,000.

If a database server is stopped (shut down) or disconnected during a scan, Trellix DLP Discover reports the run status as Stopped on the Scan Operations tab. The scan only restarts when the policy is reapplied.

Note

MySQL doesn't send a notification when the server stops running, so Trellix DLP Discover keeps running, trying to complete the scan.

Restarting Discover service in classification or remediation scans

Restarting the Discover service in the middle of a classification or remediation scan can skip some files. The persistency mechanism that restarts the scan remembers the container where the scan paused at the time that the service stopped. Scanning restarts from the beginning of that container. Sometimes a fetch task might still be running on files from the previous container when the service is stopped. When this occurs, the files are skipped. There is no way for the scan to recover these files.

Setting bandwidth for a scan

Large scans might take up noticeable bandwidth, especially on networks with low transmission capacities. By default, Trellix DLP Discover does not throttle bandwidth while scanning. If scan bandwidth is excessive, you can enable bandwidth throttling on the Scan OperationsScan Details page .

When bandwidth throttling is enabled, Trellix DLP Discover applies it to individual files being fetched rather than as an average across the entire scan. Trellix DLP Discover fetches files in blocks. The scan software checks the speed after reading each block. If it is above the set speed, the software sleeps to lower the average speed. The throughput can be above or below the configured throttle limit while fetching a block, but files are now fetched in blocks of 16 kilobits to minimize spiking. A scan might burst above or below the configured throttle limit, but the average throughput measured across the entire scan remains very close to the configured limit. When enabled, the default throttling value is 2000 KBps.