When planning and configuring your scans, consider these items.
Directory exclusion
To avoid negative performance impacts, exclude Trellix DLP Discover – SaaS directories and processes from these applications:
Antivirus software, including Trellix VirusScan Enterprise
Trellix Host Intrusion Prevention and other Trellix software
Firewalls
Access protection software
On-access scanning
Type | Exclude |
|---|---|
Processes |
|
Directories |
|
Registry keys |
|
Repository definitions
Configuring repository locations in ePO - SaaS has these limitations:
IP address ranges are supported for Class C addresses only.
IP address ranges can't include addresses ending in 0 or 255.
Note
You can define a single IP address ending in 0 or 255.
Restarting Discover service in classification or remediation scans
Restarting the Discover service in the middle of a classification or remediation scan can skip some files. The persistency mechanism that restarts the scan remembers the container where the scan paused at the time that the service stopped. Scanning restarts from the beginning of that container. Sometimes a fetch task might still be running on files from the previous container when the service is stopped. When this occurs, the files are skipped. There is no way for the scan to recover these files.
Setting bandwidth for a scan
Large scans might take up noticeable bandwidth, especially on networks with low transmission capacities. By default, Trellix DLP Discover – SaaS does not throttle bandwidth while scanning. If scan bandwidth is excessive, you can enable bandwidth throttling when you are creating a scan from the Scan Management page.
When bandwidth throttling is enabled, Trellix DLP Discover – SaaS applies it to individual files being fetched rather than as an average across the entire scan. Trellix DLP Discover – SaaS fetches files in blocks. The scan software checks the speed after reading each block. If it is above the set speed, the software sleeps to lower the average speed. The throughput can be above or below the configured throttle limit while fetching a block, but files are now fetched in blocks of 16 kilobits to minimize spiking. A scan might burst above or below the configured throttle limit, but the average throughput measured across the entire scan remains very close to the configured limit. When enabled, the default throttling value is 2000 KBps.