Scan considerations and limitations

Prev Next

When planning and configuring your scans, consider these items.

Directory exclusion

To avoid negative performance impacts, exclude Trellix DLP Discover – SaaS directories and processes from these applications:

  • Antivirus software, including Trellix VirusScan Enterprise

  • Trellix Host Intrusion Prevention and other Trellix software

  • Firewalls

  • Access protection software

  • On-access scanning

Trellix DLP Discover – SaaS Items to exclude

Type

Exclude

Processes

  • dscrawler.exe

  • dseng.exe

  • dssvc.exe

  • dstex.exe

Directories

  • c:\programdata\mcafee\discoverserver

  • c:\program files\mcafee\discoverserver

Registry keys

  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\DiscoverServer

  • HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DiscoverServer

  • HKEY_LOCAL_MACHINE\SOFTWARE\ODBC.INI\McAfeeDSPostgres



Repository definitions

Configuring repository locations in ePO - SaaS has these limitations:

  • IP address ranges are supported for Class C addresses only.

  • IP address ranges can't include addresses ending in 0 or 255.

    Note

    You can define a single IP address ending in 0 or 255.

Restarting Discover service in classification or remediation scans

Restarting the Discover service in the middle of a classification or remediation scan can skip some files. The persistency mechanism that restarts the scan remembers the container where the scan paused at the time that the service stopped. Scanning restarts from the beginning of that container. Sometimes a fetch task might still be running on files from the previous container when the service is stopped. When this occurs, the files are skipped. There is no way for the scan to recover these files.

Setting bandwidth for a scan

Large scans might take up noticeable bandwidth, especially on networks with low transmission capacities. By default, Trellix DLP Discover – SaaS does not throttle bandwidth while scanning. If scan bandwidth is excessive, you can enable bandwidth throttling when you are creating a scan from the Scan Management page.

When bandwidth throttling is enabled, Trellix DLP Discover – SaaS applies it to individual files being fetched rather than as an average across the entire scan. Trellix DLP Discover – SaaS fetches files in blocks. The scan software checks the speed after reading each block. If it is above the set speed, the software sleeps to lower the average speed. The throughput can be above or below the configured throttle limit while fetching a block, but files are now fetched in blocks of 16 kilobits to minimize spiking. A scan might burst above or below the configured throttle limit, but the average throughput measured across the entire scan remains very close to the configured limit. When enabled, the default throttling value is 2000 KBps.