You can choose to add custom header values to an email message. Trellix DLP Network Prevent allows you to add three built-in custom headers and an additional custom header with the basic rule reactions when a policy is violated. The custom headers can report the number of rules and the cumulative score of all rules that violated a policy, or any other custom header value in the delivered email message.
Create a custom header definition:
In ePO - On-prem, open Data Protection → DLP Policy Manager.
Select Definitions and in the Others category, click Custom Header.
Click Actions → New Item.
In the New Custom Header Details page, enter the custom header name and header value.
The custom header name and value must be entered using ASCII values and must not contain space or colon(:). The priority of the custom header is shown in the top-down order. Click the up arrow and down arrow to change the priority.
Click Save.
Create a rule set or modify an existing rule set:
Click Actions → New Rule Set and enter the details to create the rule set. Click the rule set.
OR
Click the existing rule set to modify the rule set.
The DLP Rule Set page opens.
Create a rule or modify an existing rule:
In the DLP Rule Set → Data Protection page, click Actions → New Rule → Email Protection to create a rule.
OR
Click the existing rule to modify the rule.
Add custom headers to a rule reaction:
In the Email Protection rule page, enter the rule details, enable or disable the rule, and set the rule severity.
Set the conditions and exceptions for the rule.
Select the Reaction tab.
In the Trellix DLP Network Prevent section, set the Action to No Action or Add header X-RCIS Action.
(Optional) Configure the custom header using the Add Custom Header field. Click the three dots menu to select the custom header from the set of custom header definitions you created in Step 1. You can choose to add one custom header and the built-in custom headers for a rule. The built-in custom headers are enabled by default.
Select Report Incident.
Save the rule and click Close.
Assign the rule set to a policy and apply the policy for the changes to become effective immediately:
In the DLP Policy Manager, select Policy Assignment.
Note
Pending Changes are shown as Yes.
Select Actions → Assign Rule Sets to a policy.
Select the rule set you created.
Select Actions → Apply Selected Policies.
Click Apply policy.
Pending Changes are now shown as No.