Set up a scan

Prev Next

Discovery scans crawl the local file system or mailboxes for sensitive content.

Verify that the rule sets you want to apply to the scans have been applied to the DLP Policy. This information is displayed on the DLP PolicyRule Sets tab.

Changes in discovery setting parameters take effect on the next scan. They are not applied to scans already in progress.

  1. In ePO - SaaS, select MenuPolicyPolicy Catalog.

  2. Select ProductData Loss Prevention <version>, then select the active DLP Policy.

  3. On the Endpoint Discovery tab, select ActionsNew Endpoint Scan, then select either Local Email or Local File System.

    Note

    Trellix DLP Endpoint – SaaS for Mac only supports local file system scans.

  4. Enter a name for the scan, then select a schedule from the drop-down list.

  5. Optional: Change the Incident Handling and Error Handling defaults. Set the State to Enabled.

    Error handling determines what to report when text can't be extracted.

  6. (Optional) For local file system scans, select the checkbox in the User Interaction field to allow the user to run enabled scans before they are scheduled. You can also enable the user to perform remediation actions from the Trellix DLP Endpoint - SaaS client console.

  7. On the Folders tab, do one of the following:

    • For file system scans, select ActionsSelect Folders. Select a defined folder definition or click New Item to create one. Define the folder as Include or Exclude.

    • For email scans, select the file types (OST, PST) and the mailboxes to be scanned.

    Note

    Trellix DLP Endpoint – SaaS for Mac only supports local file system scans.

  8. (Optional) On the Filters tab (file system scans only) select ActionsSelect Filters. Select a file information definition or click New Item to create one. Define the filter as Include or Exclude. Click OK.

    The default is All Files. Defining a filter makes the scan more efficient.

  9. On the Rules tab, verify the rules that apply.

    All discovery rules from rule sets applied to the policy are run.