The version of EDM in Trellix DLP Network Prevent v11.6, Trellix DLP Network Monitor v11.6, Trellix DLP Discover v11.7 and earlier releases is superseded with EDM (Enhanced), which is a more scalable solution. While this release continues to support both versions of EDM, we recommend that you move to the newer EDM version as the previous EDM solution will be removed in a future Trellix DLP product release.
If you do not select to change the version of EDM for scanning, the existing EDM classification continues to work until it is removed.
An appliance running Trellix DLP Network Prevent v11.8 or Trellix DLP Network Monitor v11.8 and Trellix DLP Discover v11.10 can scan for either EDM (Enhanced) or the older version of EDM - it can't scan for both at the same time. If only one type of EDM classification is present in the policy received, it will be used. If both types of EDM policies are present, a setting in the Server Configuration policy decides which version of EDM will be used. By default, EDM (Enhanced) takes priority if both are present. To set the preference:
In ePO - On-prem, select Menu → Policy → Policy Catalog.
In ePO - On-prem 5.10.x, select Data Loss Prevention <version>.
In ePO - On-prem 5.9.x and earlier, from the Product drop-down list, select Data Loss Prevention <version>.
In ePO - On-prem 5.10.x, select Server Configuration.
In ePO - On-prem 5.9.x and earlier, from the Category drop-down list, select Server Configuration.
Edit the server configuration policy and select Exact Data Matching, and then select or deselect Prefer EDM (Enhanced) based on your preference.
By default, EDM (Enhanced) is selected.
To start using EDM (Enhanced), fingerprint the data source file using the EDMTrain tool and re-create classifications using EDM (Enhanced). Select Using EDM (Enhanced) when you create New Classification Content Criteria and select the fingerprints file to switch to the EDM (Enhanced) version.
If you are already using EDM and want to upgrade to EDM (Enhanced), you must:
Set the preference to work with the older version of EDM by deselecting Prefer EDM (Enhanced) in the Server Configuration policy settings.
Deploy a test instance of a Trellix DLP Network Prevent or Trellix DLP Network Monitor server configuration policy. Assign this instance to a different server settings policy, with the preference set to EDM (Enhanced).
Create EDM (Enhanced) versions of your fingerprint file and classifications.
Set your policies to trigger based on either classification matching. (For example, Classification IS ONE OF "Customer Database EDM" OR "Customer Database EDM Enhanced").
Test your revised classification and rules.
When you are satisfied, change the preference for all appliances back to EDM (Enhanced) by selecting Prefer EDM (Enhanced) in the Server Configuration policy settings.