Use definitions and classifications to configure rules, classification criteria, and scans. All scan types require definitions.
There are two types of definitions used for Trellix DLP Discover – SaaS:
Definitions used in scans specify schedules, repositories, and credentials for repositories.
Definitions used in classifications specify what to match when crawling files, such as the file properties or the data in a file.
Definition | Used for |
|---|---|
Advanced Pattern* | Classifications |
Dictionary* | |
Document Properties | |
True File Type* | |
File Extension* | Classifications and scans |
File Information |
Note
* Indicates that predefined (built-in) definitions are available.
Classification and remediation scans use classifications to identify sensitive files and data.
Classifications use one or more definitions to match file properties and content in a file. You can use classification scans to analyze data patterns in files. Use the results of the classification scans to fine-tune your classifications, which can then be used in remediation scans.
Note
Classification and remediation scans can detect manually classified files, but Trellix DLP Discover – SaaS cannot apply manual classifications to files.
Trellix DLP Discover – SaaS can detect and identify manual or automatic classifications on files set by Trellix DLP Endpoint - SaaS.